Verification methodology

Trust is more than a
“verified” badge

We record “documented,” “implemented in source,” “covered by repository tests,” and “independently run by DSH101” as separate facts, so a discovery signal is never presented as a security conclusion.

Runnable evidence

Runtime paths: D / S / T / R

D

Docs

Official documentation states the command, configuration, or behavior.

S

Source

The official repository contains the relevant implementation, bundle, or example configuration.

T

Tests

The official repository contains related automated or snapshot tests.

R

Independent run

DSH101 recorded the environment, version, command, date, and minimum result.

Ecosystem evidence

Four progressive levels

  1. 01
    Listed

    The project and original source were discovered; structure, installation, and safety are not promised.

  2. 02
    Source reviewed

    The manifest, bundle or patch structure, license, and obvious risks were inspected.

  3. 03
    Install checked

    A pinned commit was installed in a disposable environment.

  4. 04
    Task checked

    A defined task completed in a recorded environment with a minimal retained result.