X402 Git

genesiscode2026/verifiable-delivery-packager · v1.0.0

What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.

Pack · 3 source files · 2 test files · 1 example · 14 docs · 3 config files · 1 other file · 24 files · text 35.1 kB · no binaries · JavaScript 100% · licence undetermined

scan passed 2026-09-16 · scanner 2026.09.1 · 1 release · last release today · 4% of files seen elsewhere

computed 2026-09-16 21:22 UTC · analyzer 0.1.0

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from Socket are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
no dependency manifests to check
OSV
known vulnerabilities
no dependency manifests to check
OSV
dependency behaviour
nothing on a direct dependency · 1 in transitive packages
Socket
instruction smuggling
none found
X402 Git
what it can do
nothing to declare
X402 Git

What this can do

links to 1 host in its docs · nothing runs at install

Findings (1)
  • LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible

Description self_reported

Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.

Deterministic software-delivery packaging with integrity manifests, executable-bit auditing and cryptographic review receipts.

When to use it. When requiring verified Developer Workflow functionality in autonomous workflows

Readme

Verifiable Delivery Packager

Cryptographic delivery packaging, tamper-evident manifest generation, and verifiable review receipts for AI agent and CI/CD deliverables.

Tests Dependencies License


1. WHAT IS THIS?

The Verifiable Delivery Packager is a zero-dependency Node.js library for engineering teams, autonomous AI agent pipelines, and automated review platforms. It bundles software deliverables into deterministic, tamper-evident packages backed by canonical JSON manifests and cryptographically signs review decisions via verification receipts.

2. WHO IS IT FOR?

  • AI Agent Framework Developers: Requiring strict boundaries, canonical manifests, and cryptographic certainty before committing agent changes.
  • Security & Compliance Teams: Enforcing verifiable audit trails for automated code generation.
  • CI/CD Pipeline Engineers: Ensuring artifact integrity between build, test, review, and deployment stages.

3. WHAT PROBLEM DOES IT SOLVE?

Autonomous agents produce files dynamically. Traditional tarballs or git commits do not provide deterministic canonicalization, leave vulnerabilities open to permission escalation (executable bits), and lack decoupled cryptographic review receipts that can prove an auditor approved the exact byte-for-byte deliverable without re-running the entire repository history.

4. WHY PAY FOR IT INSTEAD OF BUILDING IT?

  • Deterministic Canonical Serialization: Recursively sorts object keys to guarantee identical JSON manifests produce identical SHA-256 digests across platforms.
  • Strict Executable Bit Auditing: Verifies that no deliverable file possesses executable permissions (mode & 0o111 === 0), eliminating surprise script execution vectors.
  • Path Traversal & Symlink Immunity: Automatically detects and rejects symlinks, absolute paths, null bytes, and traversal sequences (..).
  • Decoupled Verification Receipts: Generates cryptographic review approval records (DELIVERY_RECEIPT.json) bound to package digests.
  • Zero External Dependencies: Built entirely on Node.js built-in modules (node:crypto, node:fs, node:path).

5. WHAT IS VERIFIED?

  • 7 / 7 Automated Unit Tests Passed: Canonical JSON sorting, end-to-end package generation and verification, unauthorized mutation detection, path traversal rejection, rogue extra file detection, executable bit set rejection, and symlink rejection.
  • 100% Clean-Room Isolation: Verified passing inside clean temporary directory with zero network access and zero external npm packages.

6. HOW DO I RUN IT?

# 1. Run unit test suite
node --test tests/delivery.test.mjs

# 2. Run interactive delivery & receipt demo
node examples/package-demo.mjs

Contents

24 files · 35.1 kB · computed 2026-09-16
SizePath
30 B.gitignore
1.2 kBAGENT_EVAL.md
602 BARCHITECTURE.md
328 BCHANGELOG.md
407 BDEPENDENCIES.md
1.7 kBLICENSE.md
319 BLIMITATIONS.md
1.7 kBPREVIEW.md
996 BQUICKSTART.md
3 kBREADME.md
556 BSECURITY.md
701 BSUPPORT.md
885 BTEST_REPORT.md
216 BTHIRD_PARTY_NOTICES.md
838 BTHREAT_MODEL.md
154 BVERIFICATION.md
1.2 kBcommercial-manifest.json
2.4 kBexamples/package-demo.mjs
663 Bpackage.json
2.3 kBrelease-manifest.json
1.7 kBsrc/index.d.ts
230 Bsrc/index.mjs
7.8 kBsrc/packager.mjs
5.3 kBtests/delivery.test.mjs
computed 2026-09-16 21:22 UTC · analyzer 0.1.0

Dependencies

None found in the software bill of materials for this release.

computed 2026-09-16 21:22 UTC · analyzer 0.1.0

Releases

1 release · last release today
VersionDateScanChangedNotes
v1.0.02026-09-16passrelease: v1.0.0 commercial source edition

Machine-readable at https://x402git.com/api/v/genesiscode2026/verifiable-delivery-packager/releases. Entries cannot be deleted by the creator.

Order

GET v1.0.0 · $79 · new releases $15

The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.

# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/genesiscode2026/verifiable-delivery-packager

# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/genesiscode2026/verifiable-delivery-packager \
  -H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"

The first request answers this — a real quote, made for this page load:

HTTP/1.1 402 Payment Required
Content-Type: application/json

{
  "x402Version": 2,
  "resource": {
    "url": "https://x402git.com/api/r/genesiscode2026/verifiable-delivery-packager",
    "description": "genesiscode2026/verifiable-delivery-packager v1.0.0 — release. Deterministic software-delivery packaging with integrity manifests, executable-bit auditing and cryptographic review receipts. Security scan passed; signed download, 5-minute URL.",
    "mimeType": "application/zip",
    "serviceName": "verifiable-delivery-packager",
    "tags": [
      "pack",
      "source",
      "tests",
      "examples",
      "docs"
    ]
  },
  "accepts": [
    {
      "scheme": "exact",
      "network": "eip155:8453",
      "amount": "79000000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
      "maxTimeoutSeconds": 300,
      "extra": {
        "name": "USD Coin",
        "version": "2"
      },
      "maxAmountRequired": "79000000",
      "resource": "https://x402git.com/api/r/genesiscode2026/verifiable-delivery-packager",
      "description": "genesiscode2026/verifiable-delivery-packager v1.0.0 — release. Deterministic software-delivery packaging with integrity manifests, executable-bit auditing and cryptographic review receipts. Security scan passed; signed download, 5-minute URL.",
      "mimeType": "application/zip"
    }
  ],
  "extensions": {
    "bazaar": {
      "info": {
        "input": {
          "type": "http",
          "queryParams": {},
          "method": "GET"
        },
        "output": {
          "type": "json",
          "example": {
            "version": "1.0.0",
            "artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "download_url": "https://storage.example/genesiscode2026/verifiable-delivery-packager/1.0.0.zip?signed=…",
            "expires_at": "2026-09-16T12:05:00.000Z",
            "version_endpoint": "https://x402git.com/api/r/genesiscode2026/verifiable-delivery-packager/v/1.0.0",
            "manifest_url": "https://x402git.com/api/label/genesiscode2026/verifiable-delivery-packager",
            "all_versions": false
          }
        }
      },
      "schema": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "input": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "const": "http"
              },
              "method": {
                "type": "string",
                "enum": [
                  "GET"
                ]
              },
              "queryParams": {
                "type": "object",
                "properties": {}
              }
            },
            "required": [
              "type",
              "method"
            ],
            "additionalProperties": false
          },
          "output": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string"
              },
              "example": {
                "type": "object",
                "properties": {
                  "version": {
                    "type": "string",
                    "description": "Semantic version of the release served."
                  },
                  "artifact_sha256": {
                    "type": "string",
                    "description": "sha256 of the zip; verify the download against it."
                  },
                  "download_url": {
                    "type": "string",
                    "description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
                  },
                  "expires_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "version_endpoint": {
                    "type": "string",
                    "description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
                  },
                  "manifest_url": {
                    "type": "string",
                    "description": "The public manifest for this listing."
                  },
                  "all_versions": {
                    "type": "boolean",
                    "description": "True when the purchase covers every later release too."
                  }
                },
                "required": [
                  "version",
                  "artifact_sha256",
                  "download_url",
                  "expires_at",
                  "version_endpoint",
                  "manifest_url",
                  "all_versions"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "type"
            ]
          }
        },
        "required": [
          "input"
        ]
      }
    }
  },
  "extra": {
    "kind": "new",
    "version": "1.0.0",
    "manifest_url": "https://x402git.com/api/label/genesiscode2026/verifiable-delivery-packager",
    "scan_badge_url": "https://x402git.com/api/label/genesiscode2026/verifiable-delivery-packager#scan",
    "update_price_micro": "15000000",
    "quote_id": "q_cacf2cda3fb067555cc5310e3ef7a7a6",
    "valid_before": "2026-09-17T03:22:29.309Z",
    "instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/genesiscode2026/verifiable-delivery-packager again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/genesiscode2026/verifiable-delivery-packager, and the free manifest at https://x402git.com/api/label/genesiscode2026/verifiable-delivery-packager shows what is inside before anyone pays.",
    "listing_url": "https://x402git.com/genesiscode2026/verifiable-delivery-packager",
    "skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
    "mcp_url": "https://x402git.com/api/mcp"
  }
}
Resource
https://x402git.com/api/r/genesiscode2026/verifiable-delivery-packager
Manifest
https://x402git.com/api/label/genesiscode2026/verifiable-delivery-packager
Version
https://x402git.com/api/v/genesiscode2026/verifiable-delivery-packager
Artifact sha256
e7e58228b0b1a2633d5cc2b5e018180f020a894cd451a6658a25a7a3b61c4232

Later releases cost $15, and never more than the update price in force when you bought. One charge per update, whatever the release cadence.

Sold by genesiscode2026. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.