{
  "contract": "sourcey.site-record/v1alpha1",
  "release_id": "sha256:f94358e3c57b6e575ca58c8031b9b7552cbfdb411f937b8ecdc3b042c4980a77",
  "snapshot_id": "sha256:0679a3f0d41c0733e76d10ab3fb1b331811893c7d428749740ec0f21ac731d3e",
  "artifact_sha256": "sha256:7472396c2449279d33e7a0fb2426f02a89991501262d1db8c04c81d57bdf9021",
  "data": {
    "entity_id": "ent_01kyh8fpe3xgjjktffez1t34rn",
    "entity_slug": "github",
    "profile": {
      "projection_contract": "sourcey.agent-readiness-projection/v1alpha1",
      "agent_readiness_profile_id": "arp_01kzf0m4x9v5n7pd3j2gc8q1fk",
      "entity_id": "ent_01kyh8fpe3xgjjktffez1t34rn",
      "scope": {
        "product": {
          "key": "github-rest-api",
          "name": "GitHub REST API"
        },
        "funnel": {
          "key": "repository-operations",
          "name": "Repository operations"
        }
      },
      "catalog_binding": {
        "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
        "entity_revision_digest": "sha256:984e9d33ce299c5093b358d8578a6892e03ca295907002f6ef6d3a48014088b2"
      },
      "declaration_revision_digest": "sha256:f7b1596c7450a047ff0fc2f00fa7abd83d38af8ebb6ea99003574c119d8808c1",
      "declaration": {
        "declaration_id": "declaration_github_rest_repository_operations",
        "provenance": {
          "repository": "sourcey/agent-ready-services",
          "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
          "path": "vendors/gi/github.yaml",
          "git_blob_oid": "335c7680d7edc2b4188a612523bb3cf710fab2ee",
          "blob_digest": "sha256:3cc453de44b8d230a24664a0f083f70389cfea67252045815e8feb046b863ef0"
        },
        "status": "community_declared"
      },
      "surface_catalog": {
        "assessment_targets": [
          {
            "target_id": "service-use",
            "name": "Create and manage GitHub repositories through the REST API",
            "interface_ids": [
              "repository-api"
            ]
          }
        ],
        "participants": [
          {
            "participant_id": "github",
            "roles": [
              "access_operator",
              "identity_provider",
              "operations_provider",
              "payment_provider",
              "provisioning_provider",
              "subject"
            ],
            "identity": {
              "entity_id": "ent_01kyh8fpe3xgjjktffez1t34rn"
            }
          }
        ],
        "resources": [
          {
            "resource_id": "account-signup",
            "uri": "https://github.com/signup",
            "roles": [
              "access"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "authentication",
            "uri": "https://docs.github.com/en/rest/authentication/authenticating-to-the-rest-api?apiVersion=2026-03-10",
            "roles": [
              "authentication",
              "descriptor",
              "documentation",
              "provisioning"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "billing-checkout",
            "uri": "https://docs.github.com/en/billing/how-tos/manage-plan-and-licenses/upgrade-plan",
            "roles": [
              "checkout",
              "documentation"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "pricing",
            "uri": "https://github.com/pricing",
            "roles": [
              "documentation",
              "pricing"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "rate-limits",
            "uri": "https://docs.github.com/en/rest/using-the-rest-api/rate-limits-for-the-rest-api",
            "roles": [
              "documentation",
              "operations",
              "status"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-84f7c6a9cbd0ddb3894bfc8e8f683912f976ff3f81d9c876a991c820f941f5a4",
            "uri": "https://docs.github.com/en/get-started/start-your-journey/creating-an-account-on-github",
            "roles": [
              "access",
              "documentation"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-95d77362fd899c300c1f448b97f23506087073a3e419a630603bc05f3b89eb42",
            "uri": "https://docs.github.com/en/billing/concepts/impact-of-plan-changes",
            "roles": [
              "documentation",
              "pricing"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-f867e853c07445bd6dd0ae50798b4fbbc4ef188327ba924a55ea9570e8b772bf",
            "uri": "https://docs.github.com/en/apps/creating-github-apps/authenticating-with-a-github-app/generating-a-user-access-token-for-a-github-app",
            "roles": [
              "authentication",
              "documentation"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-fa223501e9d5b0e1e036c133ac492ac85e4f34ddae80c84c00750d943c5df22d",
            "uri": "https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/token-expiration-and-revocation",
            "roles": [
              "authentication",
              "documentation"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "repository-operations",
            "uri": "https://docs.github.com/en/rest/repos/repos?apiVersion=2026-03-10",
            "roles": [
              "documentation",
              "operations",
              "provisioning",
              "status"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "rest-api",
            "uri": "https://docs.github.com/en/rest",
            "roles": [
              "discovery",
              "documentation",
              "operations"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "service-terms",
            "uri": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
            "roles": [
              "terms"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "support",
            "uri": "https://support.github.com/",
            "roles": [
              "documentation",
              "recovery"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "resource_id": "troubleshooting",
            "uri": "https://docs.github.com/en/rest/using-the-rest-api/troubleshooting-the-rest-api",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          }
        ],
        "endpoints": [
          {
            "endpoint_id": "github-api",
            "uri": "https://api.github.com",
            "transport": "http",
            "roles": [
              "service",
              "status"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "endpoint_id": "registration",
            "uri": "https://github.com/signup",
            "transport": "http",
            "roles": [
              "registration"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          }
        ],
        "interfaces": [
          {
            "interface_id": "api-authentication",
            "modality": "network_api",
            "functions": [
              "authentication"
            ],
            "endpoint_ids": [],
            "resource_ids": [
              "authentication"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          },
          {
            "interface_id": "repository-api",
            "modality": "network_api",
            "functions": [
              "service_operation"
            ],
            "endpoint_ids": [
              "github-api"
            ],
            "resource_ids": [
              "rate-limits",
              "repository-operations",
              "rest-api",
              "troubleshooting"
            ],
            "operated_by_participant_id": "github",
            "standard_bindings": []
          }
        ],
        "relations": [
          {
            "relation_id": "authentication-authenticates-api",
            "kind": "authenticates",
            "from": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "repository-api"
            }
          },
          {
            "relation_id": "relation-describes-3bdc2359067fbad866b74feffe97cfc028acfd5b0c8af44807854b8247bd4ab1",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "readiness-fa223501e9d5b0e1e036c133ac492ac85e4f34ddae80c84c00750d943c5df22d"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            }
          },
          {
            "relation_id": "relation-describes-b89359e774bb9820b9086ea0765f3845898f0e18b10eb3b73d4687dcdfa31509",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "readiness-f867e853c07445bd6dd0ae50798b4fbbc4ef188327ba924a55ea9570e8b772bf"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            }
          },
          {
            "relation_id": "repository-docs-describe-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "repository-operations"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "repository-api"
            }
          },
          {
            "relation_id": "rest-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "rest-api"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "repository-api"
            }
          },
          {
            "relation_id": "signup-precedes-authentication",
            "kind": "precedes",
            "from": {
              "node_kind": "resource",
              "node_id": "account-signup"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            }
          }
        ],
        "surface_exclusions": [
          {
            "exclusion_id": "separate-eligibility-resource",
            "role": "eligibility",
            "rationale": "Applicable access conditions are published within the service terms; no separate eligibility resource is declared."
          }
        ]
      },
      "lifecycle": "active",
      "effective_from": "2026-08-20T14:33:24.000Z",
      "revision_digest": "sha256:b05d6f473be2dfbd7fc479f349cfa8e56309312d289e830872bb5f0f317843e3",
      "policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
      "policy_version": "service-use-2026-08-20-public-evidence-r9",
      "policy_as_of": "2026-08-20T00:00:00Z",
      "assessment_basis": {
        "principal": "authorized_human_or_organization",
        "initial_state": {
          "product_specific_account": false,
          "product_credentials": false,
          "paid_subscription": false,
          "provisioned_resource": false,
          "external_identity": "only_when_declared_by_exact_funnel"
        },
        "permitted_human_boundaries": [
          "account_ownership_confirmation",
          "delegated_identity_consent",
          "regulated_approval",
          "final_payment_or_irreversible_commitment"
        ],
        "required_handoff_properties": [
          "exact_disclosure",
          "resumable_handoff",
          "deterministic_continuation"
        ],
        "forbidden_substitutions": [
          "captcha_solving",
          "human_password_or_session_sharing",
          "concealed_agent_identity",
          "invented_eligibility",
          "unbound_out_of_band_code",
          "vendor_policy_bypass",
          "unapproved_consequential_action"
        ],
        "success": {
          "target_coverage": "every_declared_target",
          "interface_coverage": "at_least_one_declared_alternative",
          "authority": "scoped",
          "failure_semantics": "documented",
          "recovery": "supported"
        },
        "observed_assessment": {
          "allowed_sources": [
            "public_documentation",
            "public_metadata",
            "public_endpoints",
            "non_mutating_interaction",
            "operator_attested_public_observation"
          ],
          "consequential_claims": "certification_required"
        }
      },
      "overall_outcome": "constrained",
      "public_state": "limited",
      "state_label": "Limited",
      "grade": "B",
      "grade_derivation": {
        "label": "Five-stage Agent Readiness report card",
        "explanation": "A through C grades count Limited stages; D and F reflect actual Blocked stages by lifecycle severity.",
        "coverage_rule": "Every core graded metric must have supported, fresh, non-conflicting evidence. Barrier checks constrain the report when verified and cap an otherwise higher grade at B+ while unverified.",
        "outcome_rule": "Each stage takes its worst core metric or verified barrier, and the overall grade is derived from the five stage states plus the explicit unverified-barrier cap."
      },
      "publication": {
        "visibility": "discoverable",
        "reasons": []
      },
      "primary_finding": {
        "stage": "evaluate",
        "stage_label": "Evaluate",
        "public_state": "limited",
        "finding": {
          "signal_code": "eligibility_decidability",
          "condition": "Can an agent decide every material eligibility condition before commitment?",
          "finding": "Only some material eligibility conditions are decidable before commitment.",
          "context": "GitHub specifies basic account signup requirements, such as providing a valid email address and complying with age and export control or sanctions laws. However, the evidence does not provide complete eligibility criteria for every organization or specialized account type."
        }
      },
      "limitations": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "finding": {
            "signal_code": "eligibility_decidability",
            "condition": "Can an agent decide every material eligibility condition before commitment?",
            "finding": "Only some material eligibility conditions are decidable before commitment.",
            "context": "GitHub specifies basic account signup requirements, such as providing a valid email address and complying with age and export control or sanctions laws. However, the evidence does not provide complete eligibility criteria for every organization or specialized account type."
          },
          "remediation": {
            "signal_code": "eligibility_decidability",
            "code": "improve.evaluate.eligibility_decidability",
            "instruction": "State every material eligibility condition and required input explicitly."
          }
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "finding": {
            "signal_code": "access_material_delivery",
            "condition": "Can usable access material be delivered securely to an authorized agent?",
            "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
            "context": "GitHub REST API documentation describes creating personal access tokens and obtaining client IDs/secrets from the developer settings page. Because credentials or access tokens involve manual dashboard steps or authorization flows, access material delivery relies on manual human creation or transfer constraints."
          },
          "remediation": {
            "signal_code": "access_material_delivery",
            "code": "improve.provision.access_material_delivery",
            "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "Documentation explicitly covers rate limit errors (403 Forbidden, 429 Too Many Requests), header-based retry guidance (retry-after, x-ratelimit-remaining, x-ratelimit-reset), exponential backoff recommendations, and API request timeout limits (10 seconds). Full cancellation, idempotency, and state reconciliation semantics are not completely established."
          },
          "remediation": {
            "signal_code": "failure_contract",
            "code": "improve.operate.failure_contract",
            "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "credential_lifecycle",
            "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
            "finding": "Only part of the credential lifecycle is agent-operable.",
            "context": "Documentation shows user access tokens can be refreshed using a refresh token and revoked by users. Third parties can also submit revocation requests for leaked tokens via the credential revocation API. Full agent-operable lifecycle and recovery are not completely established."
          },
          "remediation": {
            "signal_code": "credential_lifecycle",
            "code": "improve.operate.credential_lifecycle",
            "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
          }
        }
      ],
      "stages": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "eligibility_decidability",
            "condition": "Can an agent decide every material eligibility condition before commitment?",
            "finding": "Only some material eligibility conditions are decidable before commitment.",
            "context": "GitHub specifies basic account signup requirements, such as providing a valid email address and complying with age and export control or sanctions laws. However, the evidence does not provide complete eligibility criteria for every organization or specialized account type."
          },
          "secondary_context": [
            {
              "signal_code": "structured_evaluation_discovery",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "verified_web_agent_access",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "service_discovery",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "context": "The GitHub REST API documentation is publicly discoverable and provides overview, getting started, authentication, and endpoint guides."
            },
            {
              "signal_code": "terms_access",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "context": "The GitHub Terms of Service are retrievable and set out the general commitment terms, definitions, and rules governing the use of the Service."
            },
            {
              "signal_code": "pricing_decidability",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "context": "GitHub's pricing page explicitly states the Free tier plan costs $0 USD per month forever for basic features for individuals and organizations."
            }
          ],
          "signals": [
            {
              "signal_code": "eligibility_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Only some material eligibility conditions are decidable before commitment.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:21.721Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:09a79ceb013c949be761d5b053b4aa3cb49ae7f32520280893e709aad7102e0b",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1e52a79d1f8a550c870fe881bafa24724c2acec14d52bb0d8429a7511dd5f042",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7bfd89a57f5e3ad8283f515b259ccc091de62b6f718fd460b0dfb577d1bb91a3",
                    "sha256:d1304d267887bf3ef4bf7bebeb19eac64d52b95b3cddb5b5bd937d258f978098"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1e52a79d1f8a550c870fe881bafa24724c2acec14d52bb0d8429a7511dd5f042",
                      "start_byte": 20692,
                      "end_byte": 21492,
                      "value_digest": "sha256:ad92d6ef47999b7e97cb80ba0777774af6d5ffc1ca71605dc0de94fa5c7e8292"
                    },
                    {
                      "artifact_digest": "sha256:1e52a79d1f8a550c870fe881bafa24724c2acec14d52bb0d8429a7511dd5f042",
                      "start_byte": 23095,
                      "end_byte": 23898,
                      "value_digest": "sha256:26504a195863c02e150365161b8dfaede378fcc7ee831ebf6b6624f393d04c36"
                    }
                  ]
                }
              ],
              "note": "GitHub specifies basic account signup requirements, such as providing a valid email address and complying with age and export control or sanctions laws. However, the evidence does not provide complete eligibility criteria for every organization or specialized account type.",
              "remediation": {
                "signal_code": "eligibility_decidability",
                "code": "improve.evaluate.eligibility_decidability",
                "instruction": "State every material eligibility condition and required input explicitly."
              }
            },
            {
              "signal_code": "pricing_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:11.143Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-95d77362fd899c300c1f448b97f23506087073a3e419a630603bc05f3b89eb42"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ac304d58128e4068539c625f511482ec9d957213475803a4d3df98c01ee12eb0",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:13bd032a95d23a772d2f40cd5ca01adfb8d9b011408a459e5b0b0296bc982322",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:a592df7b04e11f8fa95255034f96634c413da6944fefb4db4717951b8806c830",
                    "sha256:e3fd83fdd8e1e39536eb5cfcd1d5fe01970403d77b99881528fca6c92f465498"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e3fd83fdd8e1e39536eb5cfcd1d5fe01970403d77b99881528fca6c92f465498",
                      "start_byte": 12851,
                      "end_byte": 13647,
                      "value_digest": "sha256:b7a8b414a2ecf387aeaca7b138abc523deb01aa23e080aab65c626c417785fa4"
                    }
                  ]
                }
              ],
              "note": "GitHub's pricing page explicitly states the Free tier plan costs $0 USD per month forever for basic features for individuals and organizations."
            },
            {
              "signal_code": "service_discovery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.087Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "rest-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:15fc1c6e65656f621ee4f88ca2bb018ea877ffe91e59f6387259692ee9d1d38a",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:116c678556732257160c4769c0892f30d9ec3677f1bbe3fa689238ec8b019acb",
                    "sha256:4ba86c08fbef4230e58f8b90f763aacb5b5a3476fd6148513a6a9e3290a4c935",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:6fe2c7d573ba6092975d2626a2b7e13aa5e762346878e93224b59a82cfba4e46"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "rest-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:4ba86c08fbef4230e58f8b90f763aacb5b5a3476fd6148513a6a9e3290a4c935",
                      "start_byte": 16211,
                      "end_byte": 16994,
                      "value_digest": "sha256:0acc0d7b6d745a562b69743bde7f5f1d4e5a67b34e60702d121854253091db00"
                    },
                    {
                      "artifact_digest": "sha256:4ba86c08fbef4230e58f8b90f763aacb5b5a3476fd6148513a6a9e3290a4c935",
                      "start_byte": 0,
                      "end_byte": 726,
                      "value_digest": "sha256:f37e20f82054a3961d2ded95d8c4f74f011c02ac63648096cc8abb070ab6586d"
                    }
                  ]
                }
              ],
              "note": "The GitHub REST API documentation is publicly discoverable and provides overview, getting started, authentication, and endpoint guides."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "terms_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:21.721Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:09a79ceb013c949be761d5b053b4aa3cb49ae7f32520280893e709aad7102e0b",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1e52a79d1f8a550c870fe881bafa24724c2acec14d52bb0d8429a7511dd5f042",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7bfd89a57f5e3ad8283f515b259ccc091de62b6f718fd460b0dfb577d1bb91a3",
                    "sha256:bc6cc0f8d816a4d956db601e032e31c02aa9ddb3f67612283f146a60eb29b59b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1e52a79d1f8a550c870fe881bafa24724c2acec14d52bb0d8429a7511dd5f042",
                      "start_byte": 12651,
                      "end_byte": 13446,
                      "value_digest": "sha256:2437eceedc60d78840c78f21b0f18a7db41b8c07928f6456dd6b2f3644d32803"
                    },
                    {
                      "artifact_digest": "sha256:1e52a79d1f8a550c870fe881bafa24724c2acec14d52bb0d8429a7511dd5f042",
                      "start_byte": 13447,
                      "end_byte": 14242,
                      "value_digest": "sha256:81539085b2c0bc30c22cd9d0ae51d99472fa63b396cdf9b63fe2e720b0f51cf7"
                    }
                  ]
                }
              ],
              "note": "The GitHub Terms of Service are retrievable and set out the general commitment terms, definitions, and rules governing the use of the Service."
            },
            {
              "signal_code": "verified_web_agent_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "eligibility_decidability",
              "code": "improve.evaluate.eligibility_decidability",
              "instruction": "State every material eligibility condition and required input explicitly."
            }
          ]
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "access_entrypoint_stability",
            "condition": "Is there a stable route to begin obtaining service access?",
            "finding": "A stable canonical route begins the required access bootstrap.",
            "context": "First-party documentation explicitly directs users to https://github.com/signup to begin personal account registration."
          },
          "secondary_context": [
            {
              "signal_code": "access_control_operability",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained registration capture returned a 403 response requiring JS and ad blocker adjustments, leaving access control operability unresolved."
            },
            {
              "signal_code": "captcha_compatible_access",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The registration endpoints returned 403 responses, and the documentation capture does not state whether a CAPTCHA boundary exists or is bypassable."
            },
            {
              "signal_code": "phone_verification_compatible",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "Retained evidence does not state whether phone verification is required or how phone verification is handled during signup."
            },
            {
              "signal_code": "delegated_identity_access",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.",
              "context": "GitHub documentation provides explicit mechanisms for obtaining fine-grained personal access tokens and OAuth tokens with specific permissions and explicit revocation options."
            }
          ],
          "signals": [
            {
              "signal_code": "access_control_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:16.102Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The retained registration capture returned a 403 response requiring JS and ad blocker adjustments, leaving access control operability unresolved."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:57.551Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "account-signup"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-84f7c6a9cbd0ddb3894bfc8e8f683912f976ff3f81d9c876a991c820f941f5a4"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:e913cc130ffc04a341bacbc18e7a0c4f79dfe2f42f0077bde4c446bd2df48e37",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4829c499f25e51b4a2e5b74e43db66ee6f07d9d74a3ea189d74bc7260f25ed84",
                    "sha256:705abaa13e74c4213739191eb64c89db2ac0c9b276ec921d9df7d37743d94b06",
                    "sha256:82d48b1d2e28cf8e2e712781f9f37b409116b73c3b1af59c3a04acbc4b27ecd3",
                    "sha256:898fd23d09aeb5aeaf7c34fba03e0fba8eecfee7bbc1ae2daef444150f6482c2",
                    "sha256:9097c682c97044db7bd80bf36035494303d35d7ca8f59c6da991e4cf676cc083",
                    "sha256:f47a5defe2737848c867834f4d9125db495642d65ca91356bc063b0a7f52f532"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-84f7c6a9cbd0ddb3894bfc8e8f683912f976ff3f81d9c876a991c820f941f5a4"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:f47a5defe2737848c867834f4d9125db495642d65ca91356bc063b0a7f52f532",
                      "start_byte": 10726,
                      "end_byte": 11526,
                      "value_digest": "sha256:1ed2dc7f5357998949393bc5879438fa5fb56d305d949b7e5f522d5cc4eecc57"
                    }
                  ]
                }
              ],
              "note": "First-party documentation explicitly directs users to https://github.com/signup to begin personal account registration."
            },
            {
              "signal_code": "captcha_compatible_access",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:57.551Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                },
                {
                  "node_kind": "resource",
                  "node_id": "account-signup"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-84f7c6a9cbd0ddb3894bfc8e8f683912f976ff3f81d9c876a991c820f941f5a4"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The registration endpoints returned 403 responses, and the documentation capture does not state whether a CAPTCHA boundary exists or is bypassable."
            },
            {
              "signal_code": "delegated_identity_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:23.282Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "authentication"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-f867e853c07445bd6dd0ae50798b4fbbc4ef188327ba924a55ea9570e8b772bf"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-fa223501e9d5b0e1e036c133ac492ac85e4f34ddae80c84c00750d943c5df22d"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:77815486230e032fd90b14312e1d67daebbe7c6d308fc4194c60d7a49e628b2d",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:8c3cc844638717b3c0d2de38b7dac74bb58c95290e10858516ed90b1ae2622dc",
                    "sha256:bbb07cc226a9a6c5eebe98f1f16a58a6995946c87a7379103b9687e1102a0dd7",
                    "sha256:ee4ac12114353f8a263d493bc4d376f6817961de1d20e8b44284be0114b7fc5e"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:bbb07cc226a9a6c5eebe98f1f16a58a6995946c87a7379103b9687e1102a0dd7",
                      "start_byte": 17575,
                      "end_byte": 18374,
                      "value_digest": "sha256:f589fd293dea1ae19e385b77d09d335985246a902694aa8fc72e67725e101d19"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ad26c365a188f67059c0ae8220300791184bc5efe27634c53c1cb3a9e5829872",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:d22731de3189b1c583cde6cb0de1e171e0570fd45209d38f3f0ea11764071387",
                    "sha256:f074290a33896fb046b07aa1ab40b30f8f5a953602d9e01959f6658a9879a09b",
                    "sha256:f989c44871fa242cf24cc6e62c9022112adfd1697586db1a17a09e0b9746f6a4"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-fa223501e9d5b0e1e036c133ac492ac85e4f34ddae80c84c00750d943c5df22d"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:f074290a33896fb046b07aa1ab40b30f8f5a953602d9e01959f6658a9879a09b",
                      "start_byte": 13797,
                      "end_byte": 14596,
                      "value_digest": "sha256:cd3f2c387575c3c1c6f09df8a91eb078060a044b7740048f39b6907c92dc7c1a"
                    }
                  ]
                }
              ],
              "note": "GitHub documentation provides explicit mechanisms for obtaining fine-grained personal access tokens and OAuth tokens with specific permissions and explicit revocation options."
            },
            {
              "signal_code": "phone_verification_compatible",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:57.551Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "account-signup"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-84f7c6a9cbd0ddb3894bfc8e8f683912f976ff3f81d9c876a991c820f941f5a4"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "Retained evidence does not state whether phone verification is required or how phone verification is handled during signup."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
            "context": "GitHub discloses the pricing structure (Free at $0 USD per month) and documents the commercial commitment conditions, including immediate prorated billing for upgrades/added seats and cycle-end effective dates for downgrades."
          },
          "secondary_context": [
            {
              "signal_code": "checkout_operability",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence describes UI navigation steps for upgrading an account plan, but does not provide evidence for deterministic API or web flow construction, approval handoff, and resumption required for checkout operability."
            },
            {
              "signal_code": "payment_authorization",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The documentation describes selecting payment methods (credit card or PayPal) and submitting upgrade forms, but does not establish scoped agent delegation or explicit human-confirmed authorization rails with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "context": "GitHub explicitly documents a direct, self-service path to upgrade personal or organization accounts under Billing and licensing settings without requiring vendor sales interaction or vendor approval."
            }
          ],
          "signals": [
            {
              "signal_code": "checkout_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:59.855Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The retained evidence describes UI navigation steps for upgrading an account plan, but does not provide evidence for deterministic API or web flow construction, approval handoff, and resumption required for checkout operability."
            },
            {
              "signal_code": "commitment_disclosure",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is the exact commercial commitment disclosed before authorization?",
              "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:36.667Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-95d77362fd899c300c1f448b97f23506087073a3e419a630603bc05f3b89eb42"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:307a23348efe6af5f73b363b4d7d84992d7e21cb3c3ec5b65ff9af197bd71bc2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:517e21b45b461ae933fe5cc274cfe61e8535ae5cc0974f6289066a5097e97fc9",
                    "sha256:5a8a92c935219f6b06b4835bb1b2f6291f89057f9e1744e4ffb8bfd2d4646628",
                    "sha256:7171d24aa22be951aab41f363390620cfdcfba009c6c60a7057f95e1819621df"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-95d77362fd899c300c1f448b97f23506087073a3e419a630603bc05f3b89eb42"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:517e21b45b461ae933fe5cc274cfe61e8535ae5cc0974f6289066a5097e97fc9",
                      "start_byte": 10246,
                      "end_byte": 11043,
                      "value_digest": "sha256:a16db80df0f0fe7cd9409354940aa61a5ab6e376eed00b3af4ce776b27bd0f50"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ac304d58128e4068539c625f511482ec9d957213475803a4d3df98c01ee12eb0",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:13bd032a95d23a772d2f40cd5ca01adfb8d9b011408a459e5b0b0296bc982322",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:a592df7b04e11f8fa95255034f96634c413da6944fefb4db4717951b8806c830",
                    "sha256:e3fd83fdd8e1e39536eb5cfcd1d5fe01970403d77b99881528fca6c92f465498"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e3fd83fdd8e1e39536eb5cfcd1d5fe01970403d77b99881528fca6c92f465498",
                      "start_byte": 12851,
                      "end_byte": 13647,
                      "value_digest": "sha256:b7a8b414a2ecf387aeaca7b138abc523deb01aa23e080aab65c626c417785fa4"
                    }
                  ]
                }
              ],
              "note": "GitHub discloses the pricing structure (Free at $0 USD per month) and documents the commercial commitment conditions, including immediate prorated billing for upgrades/added seats and cycle-end effective dates for downgrades."
            },
            {
              "signal_code": "payment_authorization",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:59.855Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The documentation describes selecting payment methods (credit card or PayPal) and submitting upgrade forms, but does not establish scoped agent delegation or explicit human-confirmed authorization rails with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:59.855Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:b40aa5e48ce7cc62d38a4268b8d9645bc02756647a4662b5a67448b44109656e",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:24805eed54af8b43110fd2bf612cf49e19de1f32d13a36997e0b5f0dcd8d5498",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:a3d33a7694b439ce416a0834ff6fc9c47a3e1ca69e0fc5db46aaad36466504c4",
                    "sha256:e4bcde011a10338716d6ea8c5c33106af591dc744b3b31ed80eb449b968ce453"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "billing-checkout"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:a3d33a7694b439ce416a0834ff6fc9c47a3e1ca69e0fc5db46aaad36466504c4",
                      "start_byte": 11934,
                      "end_byte": 12734,
                      "value_digest": "sha256:07412d031c1b30970f434d48afd203c146d571417850e3fbba5f67c8078244a6"
                    },
                    {
                      "artifact_digest": "sha256:a3d33a7694b439ce416a0834ff6fc9c47a3e1ca69e0fc5db46aaad36466504c4",
                      "start_byte": 12735,
                      "end_byte": 13535,
                      "value_digest": "sha256:6a472cb2c4fec1a8f4e5878a97a783444acd3046edef8b02af794043ad71a842"
                    }
                  ]
                }
              ],
              "note": "GitHub explicitly documents a direct, self-service path to upgrade personal or organization accounts under Billing and licensing settings without requiring vendor sales interaction or vendor approval."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "access_material_delivery",
            "condition": "Can usable access material be delivered securely to an authorized agent?",
            "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
            "context": "GitHub REST API documentation describes creating personal access tokens and obtaining client IDs/secrets from the developer settings page. Because credentials or access tokens involve manual dashboard steps or authorization flows, access material delivery relies on manual human creation or transfer constraints."
          },
          "secondary_context": [
            {
              "signal_code": "provisioning_operability",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "context": "Repository creation can be triggered directly via HTTP POST requests to API endpoints like `/orgs/{org}/repos` or `/user/repos` using bearer token authorization."
            },
            {
              "signal_code": "provisioning_completion",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.",
              "context": "Documentation for REST API repository endpoints shows synchronous endpoints returning a 201 Created HTTP response status code with the created repository schema upon successful execution."
            }
          ],
          "signals": [
            {
              "signal_code": "access_material_delivery",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:19.137Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "authentication"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-f867e853c07445bd6dd0ae50798b4fbbc4ef188327ba924a55ea9570e8b772bf"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-fa223501e9d5b0e1e036c133ac492ac85e4f34ddae80c84c00750d943c5df22d"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:77815486230e032fd90b14312e1d67daebbe7c6d308fc4194c60d7a49e628b2d",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:33c0fee92384401366a7a22b88e9f13a4592a8b774af126f48b2cd146b747286",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:8c3cc844638717b3c0d2de38b7dac74bb58c95290e10858516ed90b1ae2622dc",
                    "sha256:bbb07cc226a9a6c5eebe98f1f16a58a6995946c87a7379103b9687e1102a0dd7"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:bbb07cc226a9a6c5eebe98f1f16a58a6995946c87a7379103b9687e1102a0dd7",
                      "start_byte": 19175,
                      "end_byte": 19967,
                      "value_digest": "sha256:e62d6e3275096512ce6e0f209410fbda76ca8bbc57a5332ba147b79386cb3c30"
                    },
                    {
                      "artifact_digest": "sha256:bbb07cc226a9a6c5eebe98f1f16a58a6995946c87a7379103b9687e1102a0dd7",
                      "start_byte": 23945,
                      "end_byte": 24740,
                      "value_digest": "sha256:e4dc03c0316d2af5f279ddb8cc3fb70ba9e86056cb558872d04daeed83b60524"
                    }
                  ]
                }
              ],
              "note": "GitHub REST API documentation describes creating personal access tokens and obtaining client IDs/secrets from the developer settings page. Because credentials or access tokens involve manual dashboard steps or authorization flows, access material delivery relies on manual human creation or transfer constraints.",
              "remediation": {
                "signal_code": "access_material_delivery",
                "code": "improve.provision.access_material_delivery",
                "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
              }
            },
            {
              "signal_code": "provisioning_completion",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:52.087Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "repository-operations"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1ceb6bd307c9e14a00873cb28206fcb38c456633148e9a5ac6b4f6948146eea1",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:14ec3bdc1a4d8a7bc7eb31b01347d60f3a93e73fa0b0fb9a35e35d9a3b8c9509",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:6818003aded5539be919340d4c79eb717d4389a40ad29271a5b25a37e08c93c4",
                    "sha256:7c53dfbd53eebd5ab7d13453e49e67f4cdefec50b6b4bb97a48130780f610344"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "repository-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:14ec3bdc1a4d8a7bc7eb31b01347d60f3a93e73fa0b0fb9a35e35d9a3b8c9509",
                      "start_byte": 177047,
                      "end_byte": 177775,
                      "value_digest": "sha256:65698da4855059c0065f2284dcd3b087d1b66496d88c77ec56e177c323c80c0b"
                    },
                    {
                      "artifact_digest": "sha256:14ec3bdc1a4d8a7bc7eb31b01347d60f3a93e73fa0b0fb9a35e35d9a3b8c9509",
                      "start_byte": 219870,
                      "end_byte": 220661,
                      "value_digest": "sha256:120f2d402b1ec35be35a91676057c1b444c7774126b542399cca7640722cfb6f"
                    }
                  ]
                }
              ],
              "note": "Documentation for REST API repository endpoints shows synchronous endpoints returning a 201 Created HTTP response status code with the created repository schema upon successful execution."
            },
            {
              "signal_code": "provisioning_operability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:52.087Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "authentication"
                },
                {
                  "node_kind": "resource",
                  "node_id": "repository-operations"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1ceb6bd307c9e14a00873cb28206fcb38c456633148e9a5ac6b4f6948146eea1",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:14ec3bdc1a4d8a7bc7eb31b01347d60f3a93e73fa0b0fb9a35e35d9a3b8c9509",
                    "sha256:42afc39e26e6e3aecfa873a8cd632ddc592690a7644bf412c9ffaa2b129379f6",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:6818003aded5539be919340d4c79eb717d4389a40ad29271a5b25a37e08c93c4"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "repository-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:14ec3bdc1a4d8a7bc7eb31b01347d60f3a93e73fa0b0fb9a35e35d9a3b8c9509",
                      "start_byte": 220662,
                      "end_byte": 221459,
                      "value_digest": "sha256:b34531ae74b54b68b056fe7e27c55576d7365b9135ecf60712a61275a3249c19"
                    },
                    {
                      "artifact_digest": "sha256:14ec3bdc1a4d8a7bc7eb31b01347d60f3a93e73fa0b0fb9a35e35d9a3b8c9509",
                      "start_byte": 32920,
                      "end_byte": 33717,
                      "value_digest": "sha256:f4bea6cbe5c1993561073450655d2c80773b25a71dc3e42398a408819b8ff8ce"
                    }
                  ]
                }
              ],
              "note": "Repository creation can be triggered directly via HTTP POST requests to API endpoints like `/orgs/{org}/repos` or `/user/repos` using bearer token authorization."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "access_material_delivery",
              "code": "improve.provision.access_material_delivery",
              "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
            }
          ]
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "Documentation explicitly covers rate limit errors (403 Forbidden, 429 Too Many Requests), header-based retry guidance (retry-after, x-ratelimit-remaining, x-ratelimit-reset), exponential backoff recommendations, and API request timeout limits (10 seconds). Full cancellation, idempotency, and state reconciliation semantics are not completely established."
          },
          "secondary_context": [
            {
              "signal_code": "agent_protocol_interface",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "credential_lifecycle",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "context": "Documentation shows user access tokens can be refreshed using a refresh token and revoked by users. Third parties can also submit revocation requests for leaked tokens via the credential revocation API. Full agent-operable lifecycle and recovery are not completely established."
            },
            {
              "signal_code": "target_interface_access",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "context": "Machine-operable interfaces are documented and accessible across rate limits, repository operations, REST API overview, and troubleshooting targets."
            },
            {
              "signal_code": "operation_authentication",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "context": "API operations support authenticated requests with scoped authority using Bearer tokens sent in the Authorization header."
            },
            {
              "signal_code": "operation_contract",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "context": "Request and response schemas, parameters, rate limit response headers, status codes, and error header expectations (such as X-Accepted-GitHub-Permissions) are documented across all essential endpoints and troubleshooting guides."
            }
          ],
          "signals": [
            {
              "signal_code": "agent_protocol_interface",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "credential_lifecycle",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:47.144Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "authentication"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-f867e853c07445bd6dd0ae50798b4fbbc4ef188327ba924a55ea9570e8b772bf"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-fa223501e9d5b0e1e036c133ac492ac85e4f34ddae80c84c00750d943c5df22d"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ad26c365a188f67059c0ae8220300791184bc5efe27634c53c1cb3a9e5829872",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:aef3d4e7a88af82f631d9db55d21d7eb457f97bb05029b095d6d4ad3d59d848b",
                    "sha256:d22731de3189b1c583cde6cb0de1e171e0570fd45209d38f3f0ea11764071387",
                    "sha256:f074290a33896fb046b07aa1ab40b30f8f5a953602d9e01959f6658a9879a09b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-fa223501e9d5b0e1e036c133ac492ac85e4f34ddae80c84c00750d943c5df22d"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:f074290a33896fb046b07aa1ab40b30f8f5a953602d9e01959f6658a9879a09b",
                      "start_byte": 15398,
                      "end_byte": 16195,
                      "value_digest": "sha256:a73d1e2bb3cdf0edb0758dfda8cb8ebebf3196256b732d047459a471eb8dbdbc"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:60aa72bb4c337816f7042a4b6ce3118c2c562873a34acee1443e248bfc2e6399",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1209ea3a91548ead1bd71d35132aa8e63230f50a91b1ac99626e25200b52b8da",
                    "sha256:15dac92aa0cb48bd846b345dfb59c9f3d2c1756370dd41427e0ad574c5cdb27b",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:b14cd43bef83920cff60ad42c71e0d446fd07d3baf74f9950a7132db09a21813"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-f867e853c07445bd6dd0ae50798b4fbbc4ef188327ba924a55ea9570e8b772bf"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b14cd43bef83920cff60ad42c71e0d446fd07d3baf74f9950a7132db09a21813",
                      "start_byte": 19554,
                      "end_byte": 20352,
                      "value_digest": "sha256:33c65dcae4ef292b2a6ce96f0486f30d6e4646a6a402947689e712c2af81ff63"
                    }
                  ]
                }
              ],
              "note": "Documentation shows user access tokens can be refreshed using a refresh token and revoked by users. Third parties can also submit revocation requests for leaked tokens via the credential revocation API. Full agent-operable lifecycle and recovery are not completely established.",
              "remediation": {
                "signal_code": "credential_lifecycle",
                "code": "improve.operate.credential_lifecycle",
                "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
              }
            },
            {
              "signal_code": "failure_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Safe failure handling is documented only partially.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:42.349Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "troubleshooting"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:e3f222d1d922f3bc69604e7cc1789003881ca13481cae35eebd0c5fec00edd9f",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:6da88bb95530ade99e85b93719080e986d3444eeec62a65ec0a9c28a80c7e77e",
                    "sha256:732a197feb580cc3905797185a872ef5d3c5ecf4612506563040e442e2284a1c",
                    "sha256:a0359ef7fae42374e703170da2717f134165d35bb2626bf36ab9fabe5583c04f"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "troubleshooting"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:a0359ef7fae42374e703170da2717f134165d35bb2626bf36ab9fabe5583c04f",
                      "start_byte": 17038,
                      "end_byte": 17837,
                      "value_digest": "sha256:78590c366165daf20ea8c77cdc23812d936db810abc982754a1a97bda3ca87ba"
                    },
                    {
                      "artifact_digest": "sha256:a0359ef7fae42374e703170da2717f134165d35bb2626bf36ab9fabe5583c04f",
                      "start_byte": 17838,
                      "end_byte": 18632,
                      "value_digest": "sha256:92f2be204d2cac44569f28ab2b8ca40af3c585c61ff14a7a4dfd08e1b03e4355"
                    }
                  ]
                }
              ],
              "note": "Documentation explicitly covers rate limit errors (403 Forbidden, 429 Too Many Requests), header-based retry guidance (retry-after, x-ratelimit-remaining, x-ratelimit-reset), exponential backoff recommendations, and API request timeout limits (10 seconds). Full cancellation, idempotency, and state reconciliation semantics are not completely established.",
              "remediation": {
                "signal_code": "failure_contract",
                "code": "improve.operate.failure_contract",
                "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
              }
            },
            {
              "signal_code": "operation_authentication",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:47.144Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "authentication"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-f867e853c07445bd6dd0ae50798b4fbbc4ef188327ba924a55ea9570e8b772bf"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-fa223501e9d5b0e1e036c133ac492ac85e4f34ddae80c84c00750d943c5df22d"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:77815486230e032fd90b14312e1d67daebbe7c6d308fc4194c60d7a49e628b2d",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:12303fe165ea569bcd6eda0e4c5003759c7d4d8bc2d28b5116dd2f8a105d4316",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:8c3cc844638717b3c0d2de38b7dac74bb58c95290e10858516ed90b1ae2622dc",
                    "sha256:bbb07cc226a9a6c5eebe98f1f16a58a6995946c87a7379103b9687e1102a0dd7"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:bbb07cc226a9a6c5eebe98f1f16a58a6995946c87a7379103b9687e1102a0dd7",
                      "start_byte": 18375,
                      "end_byte": 19174,
                      "value_digest": "sha256:9f71d0d0716ba3e65c6a9f75a9b2977648cf6307c4825af1513ecf23ef93f0f7"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:60aa72bb4c337816f7042a4b6ce3118c2c562873a34acee1443e248bfc2e6399",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:15dac92aa0cb48bd846b345dfb59c9f3d2c1756370dd41427e0ad574c5cdb27b",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:b14cd43bef83920cff60ad42c71e0d446fd07d3baf74f9950a7132db09a21813",
                    "sha256:f9bc73227b757294063c1befb2f42a692108c2afef735254ec6a29b29d967fe2"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-f867e853c07445bd6dd0ae50798b4fbbc4ef188327ba924a55ea9570e8b772bf"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b14cd43bef83920cff60ad42c71e0d446fd07d3baf74f9950a7132db09a21813",
                      "start_byte": 26735,
                      "end_byte": 27529,
                      "value_digest": "sha256:88964c055979bc902c137b4bd2d73999aa895087f3f739ca7290aa395054c706"
                    }
                  ]
                }
              ],
              "note": "API operations support authenticated requests with scoped authority using Bearer tokens sent in the Authorization header."
            },
            {
              "signal_code": "operation_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:52.087Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "repository-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:15fc1c6e65656f621ee4f88ca2bb018ea877ffe91e59f6387259692ee9d1d38a",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:116c678556732257160c4769c0892f30d9ec3677f1bbe3fa689238ec8b019acb",
                    "sha256:4ba86c08fbef4230e58f8b90f763aacb5b5a3476fd6148513a6a9e3290a4c935",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:c9b3d64eb8e8d11fb2f45b006ff5baf27ead8f37bbd452add70fd44fa2c00202"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "rest-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:4ba86c08fbef4230e58f8b90f763aacb5b5a3476fd6148513a6a9e3290a4c935",
                      "start_byte": 16211,
                      "end_byte": 16994,
                      "value_digest": "sha256:0acc0d7b6d745a562b69743bde7f5f1d4e5a67b34e60702d121854253091db00"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:e3f222d1d922f3bc69604e7cc1789003881ca13481cae35eebd0c5fec00edd9f",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:72c222bd70e7b14285ee8808ec88586fce643d9e04e8b28c876ddc5eb108b86e",
                    "sha256:732a197feb580cc3905797185a872ef5d3c5ecf4612506563040e442e2284a1c",
                    "sha256:a0359ef7fae42374e703170da2717f134165d35bb2626bf36ab9fabe5583c04f"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "troubleshooting"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:a0359ef7fae42374e703170da2717f134165d35bb2626bf36ab9fabe5583c04f",
                      "start_byte": 28191,
                      "end_byte": 28988,
                      "value_digest": "sha256:50bc6e53522f5f19427c81ecf4a1741b7d6b1707e28dc983f4e090f00d160c94"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:16d915a166b045cd4680612ff2f9b957214e4193c3be490654359b767b0a9320",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:187dc8c39799cb1649e5bd0256a93eee92bac4c2fd5e9d7e9266bd4874c8e769",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5ad2b84c91d37968037c27916ee002b89e9a603351a1c9e9739602a00efe4551",
                    "sha256:ea43d4200dd70ac8428ebce155eed9ef5944d7a31d1f7d5fad8a9f8d2be1532c"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "rate-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ea43d4200dd70ac8428ebce155eed9ef5944d7a31d1f7d5fad8a9f8d2be1532c",
                      "start_byte": 23659,
                      "end_byte": 24446,
                      "value_digest": "sha256:beb7792283430a80a59581b9b368e6c0425fd945af0ef01ab800fb9cced9261b"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1ceb6bd307c9e14a00873cb28206fcb38c456633148e9a5ac6b4f6948146eea1",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:14ec3bdc1a4d8a7bc7eb31b01347d60f3a93e73fa0b0fb9a35e35d9a3b8c9509",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:6818003aded5539be919340d4c79eb717d4389a40ad29271a5b25a37e08c93c4",
                    "sha256:96d13887198a21f8310f84210753766be27d0919020755680ba69d47eb10058e"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "repository-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:14ec3bdc1a4d8a7bc7eb31b01347d60f3a93e73fa0b0fb9a35e35d9a3b8c9509",
                      "start_byte": 32920,
                      "end_byte": 33717,
                      "value_digest": "sha256:f4bea6cbe5c1993561073450655d2c80773b25a71dc3e42398a408819b8ff8ce"
                    }
                  ]
                }
              ],
              "note": "Request and response schemas, parameters, rate limit response headers, status codes, and error header expectations (such as X-Accepted-GitHub-Permissions) are documented across all essential endpoints and troubleshooting guides."
            },
            {
              "signal_code": "target_interface_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:52.087Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "repository-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:15fc1c6e65656f621ee4f88ca2bb018ea877ffe91e59f6387259692ee9d1d38a",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:116c678556732257160c4769c0892f30d9ec3677f1bbe3fa689238ec8b019acb",
                    "sha256:4ba86c08fbef4230e58f8b90f763aacb5b5a3476fd6148513a6a9e3290a4c935",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:c9b3d64eb8e8d11fb2f45b006ff5baf27ead8f37bbd452add70fd44fa2c00202"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "rest-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:4ba86c08fbef4230e58f8b90f763aacb5b5a3476fd6148513a6a9e3290a4c935",
                      "start_byte": 16211,
                      "end_byte": 16994,
                      "value_digest": "sha256:0acc0d7b6d745a562b69743bde7f5f1d4e5a67b34e60702d121854253091db00"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:e3f222d1d922f3bc69604e7cc1789003881ca13481cae35eebd0c5fec00edd9f",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:732a197feb580cc3905797185a872ef5d3c5ecf4612506563040e442e2284a1c",
                    "sha256:a0359ef7fae42374e703170da2717f134165d35bb2626bf36ab9fabe5583c04f",
                    "sha256:dfa8fc0e10ba8b2d577941b9b82f07d9c8c11959c1e2478cd8a539887b456001"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "troubleshooting"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:a0359ef7fae42374e703170da2717f134165d35bb2626bf36ab9fabe5583c04f",
                      "start_byte": 13089,
                      "end_byte": 13886,
                      "value_digest": "sha256:1c916ea9650a9d84da2494190cf335315c03e40b82a2b6865db4ce75818ab3b9"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1ceb6bd307c9e14a00873cb28206fcb38c456633148e9a5ac6b4f6948146eea1",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:14ec3bdc1a4d8a7bc7eb31b01347d60f3a93e73fa0b0fb9a35e35d9a3b8c9509",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:6818003aded5539be919340d4c79eb717d4389a40ad29271a5b25a37e08c93c4",
                    "sha256:b38175e7e230304e6ab81ba9c3549b6117bc132e6dfa238b13aebf2cb106a268"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "repository-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:14ec3bdc1a4d8a7bc7eb31b01347d60f3a93e73fa0b0fb9a35e35d9a3b8c9509",
                      "start_byte": 20404,
                      "end_byte": 21175,
                      "value_digest": "sha256:0010e7b91f5660370e24bdfe167786a1afe4ebf994516f9e769f1ac11801d1a4"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:16d915a166b045cd4680612ff2f9b957214e4193c3be490654359b767b0a9320",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0174c6d307642eb2242c76add63f232e446e473b14ba197dceec29d970b2f2fc",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5ad2b84c91d37968037c27916ee002b89e9a603351a1c9e9739602a00efe4551",
                    "sha256:ea43d4200dd70ac8428ebce155eed9ef5944d7a31d1f7d5fad8a9f8d2be1532c"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "rate-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ea43d4200dd70ac8428ebce155eed9ef5944d7a31d1f7d5fad8a9f8d2be1532c",
                      "start_byte": 16476,
                      "end_byte": 17275,
                      "value_digest": "sha256:60643e01e29550d6a3f4cd943b2d89023e53d50f36f91c13b38b573853668d72"
                    }
                  ]
                }
              ],
              "note": "Machine-operable interfaces are documented and accessible across rate limits, repository operations, REST API overview, and troubleshooting targets."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "failure_contract",
              "code": "improve.operate.failure_contract",
              "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
            },
            {
              "signal_code": "credential_lifecycle",
              "code": "improve.operate.credential_lifecycle",
              "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
            }
          ]
        }
      ],
      "coverage": {
        "status": "complete",
        "required_signals": 16,
        "covered_signals": 16,
        "ratio": 1,
        "barrier_signals": 5,
        "verified_barrier_signals": 0,
        "barrier_ratio": 0
      },
      "last_tested_at": "2026-08-20T15:56:59.855Z",
      "freshness": "fresh",
      "provenance": {
        "tier": "observed",
        "freshness": "fresh",
        "dispute": "none",
        "coverage_policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
        "freshness_policy_digest": "sha256:00f7f2a35f37b184e57ce2cc116f6a5e3feb4813991aacd7e29e322f2d3607a8",
        "basis_event_ids": [
          "sha256:00863e19a8e6e859e65dcbc1594c3c95b2c6363845c53748b9d1a6dc9224acbf",
          "sha256:00c13d09e1f6ef85cf1f722d3f7b965ddc77e6d0289048a1d87fac0afc6a29a8",
          "sha256:02fbf7f596e1a59449faa71c92d04fdc5677a5214b5614dcbfaa3d0b7d69e980",
          "sha256:0764663dc29383268ca1c9dce8554a51b117b6f6146fb2e0880909e6226634d8",
          "sha256:13272458c4e3ed1453791ad768a559cfabb460cf116b558e7bdb76c657adf824",
          "sha256:1610a31bb441ef3cbd907d01bc51b66afd67a7e054134e562477af2196954bb3",
          "sha256:1e99824c7c225db695923a263e24d36cc0994290f8c646c05e0dd95c721344d8",
          "sha256:32ee20a33d5c0a275eb76096d4fa7b107172a7dd9693e58356d6c6418c4ae78f",
          "sha256:37e62f4698dcf3e8e4ab114428364168de352f0b37d8f6ffc139869a8f7e74f5",
          "sha256:53db41036f67461e775831bbc05e2c33f2f7651db7a10a5f7de51370f7396cb5",
          "sha256:55393912dff5b1c7d738fbbe15e1a6d634b67af51f3c08b9a808ea819beb19b4",
          "sha256:563b5666acfbc29928cfead20e333829c6f030525b78e7afe747640dbb6e2a99",
          "sha256:585278da58654e382d6c49483ef28bcdc63e9d53d03cca664b22314a1223b5e9",
          "sha256:62332033c04c1c0a3c669f8f1f1e4201aa739a8156ded9f442248f3ef911692c",
          "sha256:675d0186af8d30c0f6a7620c0d6c8b1043d69dbb78d4bd777d5fb8f67aefaa03",
          "sha256:6b74c7be989a7f915e8a4c58b0bee87ff9807af7ddc0ab378ab3baae4e1f04f6",
          "sha256:6c8ce43ad73eec1a510748ca2806faa393fa56aeb5e5446b52250e9ac08ea551",
          "sha256:755d79f32f4b9907737ff141fa68b9781039b7c44c50ea17cbe59b8cc3234426",
          "sha256:7b6ac28bac9ae728bc0ad2830edfcc47323674dbae4ab4c015ed93a0da178b74",
          "sha256:7d5b470e5d2fea36d00a2cb6493d030070bd53d5c2609c8ce5c4ece22b488a1b",
          "sha256:89bc1bcbc99a8843b2e3ff06dad1f4df8c72155d48a51c68d9a1fc777087d6a9",
          "sha256:95b521611f2e0adfcf852db46c4d1ea4fb8bee583723273a833e92afc5aca59c",
          "sha256:9a8a83ed2158ee62d9c0122c3bf4d87cf731e0784658cd2f7d27e02af1580686",
          "sha256:9fc7cd299b6ac5710c0f10347cc9c44f5172273202e60065dfac232450477535",
          "sha256:a8b72ad76d64cdc66f310d2e901dcd887abeed6b5783e2f07e3bb4d097bf3ea6",
          "sha256:a98999b90ef4d2d3c9e842eeff46b67bc595f46cd39521e72c31f4965b7937f9",
          "sha256:aa05246dc6cbd434ab06bed4ce12843d7b24821dde8a5fd35ea2546acc808179",
          "sha256:b05b6519d25bb08822ca1b0525c8b0ab4c52896f3d4cb32bf66bd897e383be31",
          "sha256:bec9c46f8f00a06907feb544a69170b1cb91cd0ce3cdc1f2b50633806f793785",
          "sha256:c2ef1de35db7c9fec4a28189260b461a7f1678ea3ca7adfea82a357e20d029e2",
          "sha256:c388eb53eade68394c77e2715e3ca270d984578ed1c9b7fc081f9b194736459e",
          "sha256:d6b88208e3bf44ef51135b32e6c2c444b19b3a21e696de1fb897e6fc2f79c137",
          "sha256:dd461ffb0df66a055d9a65842b884d3a459cd57e3e979478be189e382c4873b1",
          "sha256:f50671812e223d05ca972c2825409354d79cd1ceb725afcf7f828805e36185eb"
        ],
        "fields": [
          {
            "path": "/signals/0",
            "supporting_event_ids": [
              "sha256:a8b72ad76d64cdc66f310d2e901dcd887abeed6b5783e2f07e3bb4d097bf3ea6"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:21.721Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/1",
            "supporting_event_ids": [
              "sha256:7d5b470e5d2fea36d00a2cb6493d030070bd53d5c2609c8ce5c4ece22b488a1b"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:11.143Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/2",
            "supporting_event_ids": [
              "sha256:f50671812e223d05ca972c2825409354d79cd1ceb725afcf7f828805e36185eb"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.087Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/3",
            "supporting_event_ids": [
              "sha256:6c8ce43ad73eec1a510748ca2806faa393fa56aeb5e5446b52250e9ac08ea551"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:21.721Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/4",
            "supporting_event_ids": [
              "sha256:53db41036f67461e775831bbc05e2c33f2f7651db7a10a5f7de51370f7396cb5"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:16.102Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/5",
            "supporting_event_ids": [
              "sha256:aa05246dc6cbd434ab06bed4ce12843d7b24821dde8a5fd35ea2546acc808179"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:57.551Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/6",
            "supporting_event_ids": [
              "sha256:1610a31bb441ef3cbd907d01bc51b66afd67a7e054134e562477af2196954bb3",
              "sha256:a98999b90ef4d2d3c9e842eeff46b67bc595f46cd39521e72c31f4965b7937f9",
              "sha256:c2ef1de35db7c9fec4a28189260b461a7f1678ea3ca7adfea82a357e20d029e2"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:57.551Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/7",
            "supporting_event_ids": [
              "sha256:1e99824c7c225db695923a263e24d36cc0994290f8c646c05e0dd95c721344d8",
              "sha256:62332033c04c1c0a3c669f8f1f1e4201aa739a8156ded9f442248f3ef911692c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:23.282Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/8",
            "supporting_event_ids": [
              "sha256:00863e19a8e6e859e65dcbc1594c3c95b2c6363845c53748b9d1a6dc9224acbf",
              "sha256:55393912dff5b1c7d738fbbe15e1a6d634b67af51f3c08b9a808ea819beb19b4"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:57.551Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/9",
            "supporting_event_ids": [
              "sha256:b05b6519d25bb08822ca1b0525c8b0ab4c52896f3d4cb32bf66bd897e383be31"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:59.855Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/10",
            "supporting_event_ids": [
              "sha256:755d79f32f4b9907737ff141fa68b9781039b7c44c50ea17cbe59b8cc3234426",
              "sha256:9fc7cd299b6ac5710c0f10347cc9c44f5172273202e60065dfac232450477535"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:36.667Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/11",
            "supporting_event_ids": [
              "sha256:d6b88208e3bf44ef51135b32e6c2c444b19b3a21e696de1fb897e6fc2f79c137"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:59.855Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/12",
            "supporting_event_ids": [
              "sha256:02fbf7f596e1a59449faa71c92d04fdc5677a5214b5614dcbfaa3d0b7d69e980"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:59.855Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/13",
            "supporting_event_ids": [
              "sha256:0764663dc29383268ca1c9dce8554a51b117b6f6146fb2e0880909e6226634d8"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:19.137Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/14",
            "supporting_event_ids": [
              "sha256:89bc1bcbc99a8843b2e3ff06dad1f4df8c72155d48a51c68d9a1fc777087d6a9"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:52.087Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/15",
            "supporting_event_ids": [
              "sha256:95b521611f2e0adfcf852db46c4d1ea4fb8bee583723273a833e92afc5aca59c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:52.087Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/16",
            "supporting_event_ids": [
              "sha256:675d0186af8d30c0f6a7620c0d6c8b1043d69dbb78d4bd777d5fb8f67aefaa03",
              "sha256:9a8a83ed2158ee62d9c0122c3bf4d87cf731e0784658cd2f7d27e02af1580686"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:47.144Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/17",
            "supporting_event_ids": [
              "sha256:37e62f4698dcf3e8e4ab114428364168de352f0b37d8f6ffc139869a8f7e74f5"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:42.349Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/18",
            "supporting_event_ids": [
              "sha256:563b5666acfbc29928cfead20e333829c6f030525b78e7afe747640dbb6e2a99",
              "sha256:7b6ac28bac9ae728bc0ad2830edfcc47323674dbae4ab4c015ed93a0da178b74"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:47.144Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/19",
            "supporting_event_ids": [
              "sha256:00c13d09e1f6ef85cf1f722d3f7b965ddc77e6d0289048a1d87fac0afc6a29a8",
              "sha256:6b74c7be989a7f915e8a4c58b0bee87ff9807af7ddc0ab378ab3baae4e1f04f6",
              "sha256:c388eb53eade68394c77e2715e3ca270d984578ed1c9b7fc081f9b194736459e",
              "sha256:dd461ffb0df66a055d9a65842b884d3a459cd57e3e979478be189e382c4873b1"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:52.087Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/20",
            "supporting_event_ids": [
              "sha256:13272458c4e3ed1453791ad768a559cfabb460cf116b558e7bdb76c657adf824",
              "sha256:32ee20a33d5c0a275eb76096d4fa7b107172a7dd9693e58356d6c6418c4ae78f",
              "sha256:585278da58654e382d6c49483ef28bcdc63e9d53d03cca664b22314a1223b5e9",
              "sha256:bec9c46f8f00a06907feb544a69170b1cb91cd0ce3cdc1f2b50633806f793785"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:52.087Z",
            "freshness": "fresh"
          }
        ]
      },
      "canonical_url": "https://sourcey.com/catalog/github/agent-readiness/github-rest-api/repository-operations",
      "projection_digest": "sha256:3882c657abb37b5f45540c7ab7e6be96d111d939cab03d72e6235fac6c771647"
    }
  }
}
