{
  "schema": "cadence.public-trust-evidence",
  "schema_version": 1,
  "snapshot_id": "20260917T123743Z-b047d59a3681",
  "snapshot_url": "https://emixd12.github.io/habit-tracking-app/trust/35222021571/dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs/dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV/20260917T123743Z-b047d59a3681.json",
  "source_commit": "b047d59a368136f283cf981f42e21b937ec13101",
  "application_deployment": {
    "id": "dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs",
    "url": "https://cadence-blush-three.vercel.app"
  },
  "marketing_deployment": {
    "id": "dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV",
    "url": "https://cadence-marketing-two.vercel.app"
  },
  "workflow_run": {
    "id": "35222021571",
    "url": "https://github.com/emixd12/habit-tracking-app/actions/runs/35222021571"
  },
  "built_at": "2026-09-17T12:37:43Z",
  "verified_at": "2026-09-17T12:37:43Z",
  "freshness_deadline": "2026-09-18T12:37:43Z",
  "checks": [
    {
      "id": "source_to_deployment_provenance",
      "status": "failed",
      "scope": "Both named Ready Vercel deployments and their public Git commit metadata.",
      "scope_limit": "It does not prove that later configuration or provider state is unchanged.",
      "tool": {
        "name": "Vercel REST API",
        "version": "1"
      },
      "completed_at": "2026-09-17T12:37:43Z",
      "freshness_deadline": "2026-09-18T12:37:43Z",
      "summary": "The named deployments are not both Ready from the expected source commit.",
      "unavailable_reason": null,
      "evidence_url": "https://emixd12.github.io/habit-tracking-app/trust/35222021571/dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs/dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV/20260917T123743Z-b047d59a3681.details.json",
      "source_commit": "b047d59a368136f283cf981f42e21b937ec13101",
      "application_deployment_id": "dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs",
      "marketing_deployment_id": "dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV"
    },
    {
      "id": "production_dependency_vulnerabilities",
      "status": "unavailable",
      "scope": "Production dependencies declared by the lockfile, npm advisory data, and Dependabot status.",
      "scope_limit": "It covers declared production dependencies and the tool's data at completion time only.",
      "tool": {
        "name": "npm audit",
        "version": "11.19.0"
      },
      "completed_at": null,
      "freshness_deadline": null,
      "summary": "SBOM has 253 components with SHA-256 a83638268de169098cc8759be1f89a35360eeeb49dbc227c44a23bd330b08b4c; audit totals: 5 (1 critical, 3 high, 1 moderate, 0 low); Dependabot aggregate unavailable.",
      "unavailable_reason": "The workflow token could not read the Dependabot aggregate result.",
      "evidence_url": "https://emixd12.github.io/habit-tracking-app/trust/35222021571/dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs/dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV/20260917T123743Z-b047d59a3681.details.json",
      "source_commit": "b047d59a368136f283cf981f42e21b937ec13101",
      "application_deployment_id": "dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs",
      "marketing_deployment_id": "dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV"
    },
    {
      "id": "code_scanning",
      "status": "passed",
      "scope": "Configured GitHub code-scanning analyzers for the named public repository and source commit.",
      "scope_limit": "It covers configured analyzers and rules only and cannot establish the absence of defects.",
      "tool": {
        "name": "GitHub CodeQL",
        "version": "1"
      },
      "completed_at": "2026-09-17T12:37:43Z",
      "freshness_deadline": "2026-09-24T12:37:43Z",
      "summary": "CodeQL completed for the named commit and reported zero open repository alerts.",
      "unavailable_reason": null,
      "evidence_url": "https://emixd12.github.io/habit-tracking-app/trust/35222021571/dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs/dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV/20260917T123743Z-b047d59a3681.details.json",
      "source_commit": "b047d59a368136f283cf981f42e21b937ec13101",
      "application_deployment_id": "dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs",
      "marketing_deployment_id": "dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV"
    },
    {
      "id": "secret_scanning",
      "status": "unavailable",
      "scope": "GitHub secret scanning and push protection for the named public repository.",
      "scope_limit": "It covers patterns and repository history visible to the configured platform only.",
      "tool": {
        "name": "GitHub secret scanning",
        "version": "1"
      },
      "completed_at": null,
      "freshness_deadline": null,
      "summary": "The provider did not expose a safe aggregate result.",
      "unavailable_reason": "The workflow token could not read this aggregate provider result.",
      "evidence_url": "https://emixd12.github.io/habit-tracking-app/trust/35222021571/dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs/dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV/20260917T123743Z-b047d59a3681.details.json",
      "source_commit": "b047d59a368136f283cf981f42e21b937ec13101",
      "application_deployment_id": "dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs",
      "marketing_deployment_id": "dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV"
    },
    {
      "id": "public_artifact_integrity",
      "status": "passed",
      "scope": "6 allowlisted public application and marketing assets.",
      "scope_limit": "It covers generated public files, not private operational records or live-route availability.",
      "tool": {
        "name": "SHA-256",
        "version": "1"
      },
      "completed_at": "2026-09-17T12:37:43Z",
      "freshness_deadline": "2026-09-18T12:37:43Z",
      "summary": "6 of 6 public assets matched status, type, size, and digest bounds.",
      "unavailable_reason": null,
      "evidence_url": "https://emixd12.github.io/habit-tracking-app/trust/35222021571/dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs/dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV/20260917T123743Z-b047d59a3681.details.json",
      "source_commit": "b047d59a368136f283cf981f42e21b937ec13101",
      "application_deployment_id": "dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs",
      "marketing_deployment_id": "dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV"
    },
    {
      "id": "application_live_route_comparison",
      "status": "passed",
      "scope": "10 explicit unauthenticated application route contracts.",
      "scope_limit": "It covers the sampled routes and responses at completion time, not every authenticated workflow.",
      "tool": {
        "name": "Cadence route comparator",
        "version": "1"
      },
      "completed_at": "2026-09-17T12:37:43Z",
      "freshness_deadline": "2026-09-18T12:37:43Z",
      "summary": "10 of 10 application routes matched the registry.",
      "unavailable_reason": null,
      "evidence_url": "https://emixd12.github.io/habit-tracking-app/trust/35222021571/dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs/dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV/20260917T123743Z-b047d59a3681.details.json",
      "source_commit": "b047d59a368136f283cf981f42e21b937ec13101",
      "application_deployment_id": "dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs",
      "marketing_deployment_id": "dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV"
    },
    {
      "id": "marketing_live_route_comparison",
      "status": "passed",
      "scope": "17 generated marketing HTML and Markdown route contracts.",
      "scope_limit": "It covers declared marketing routes at completion time, not every external cache or network path.",
      "tool": {
        "name": "Cadence route comparator",
        "version": "1"
      },
      "completed_at": "2026-09-17T12:37:43Z",
      "freshness_deadline": "2026-09-18T12:37:43Z",
      "summary": "17 of 17 marketing routes matched the generated manifest.",
      "unavailable_reason": null,
      "evidence_url": "https://emixd12.github.io/habit-tracking-app/trust/35222021571/dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs/dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV/20260917T123743Z-b047d59a3681.details.json",
      "source_commit": "b047d59a368136f283cf981f42e21b937ec13101",
      "application_deployment_id": "dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs",
      "marketing_deployment_id": "dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV"
    },
    {
      "id": "hosted_migration_boundary",
      "status": "failed",
      "scope": "Hosted Supabase migration history compared with the tracked migration boundary.",
      "scope_limit": "It proves migration-history alignment only, not correctness of user-owned data.",
      "tool": {
        "name": "Supabase Management API",
        "version": "v1 migration inventory"
      },
      "completed_at": "2026-09-17T12:37:43Z",
      "freshness_deadline": "2026-09-18T12:37:43Z",
      "summary": "Hosted migration boundary does not match the tracked source boundary.",
      "unavailable_reason": null,
      "evidence_url": "https://emixd12.github.io/habit-tracking-app/trust/35222021571/dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs/dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV/20260917T123743Z-b047d59a3681.details.json",
      "source_commit": "b047d59a368136f283cf981f42e21b937ec13101",
      "application_deployment_id": "dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs",
      "marketing_deployment_id": "dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV"
    },
    {
      "id": "cross_account_rls_isolation",
      "status": "not_run",
      "scope": "Disposable-account ordinary-client ownership checks across the public data API.",
      "scope_limit": "It covers only the tested tables and operations at completion time.",
      "tool": {
        "name": "Cadence RLS smoke",
        "version": "1"
      },
      "completed_at": null,
      "freshness_deadline": null,
      "summary": "The authorized cross-account RLS smoke did not run in this collection.",
      "unavailable_reason": null,
      "evidence_url": "https://emixd12.github.io/habit-tracking-app/trust/35222021571/dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs/dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV/20260917T123743Z-b047d59a3681.details.json",
      "source_commit": "b047d59a368136f283cf981f42e21b937ec13101",
      "application_deployment_id": "dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs",
      "marketing_deployment_id": "dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV"
    }
  ]
}
