Preflight input
Fetching contacts only GitHub's public API. Leave blank to work entirely offline with pasted JSON.
Patterns are JavaScript regular expressions. Match every filename from start to finish with ^ and $.
Required fields: release and required. Optional: checksumFiles and references.
Accepts a GitHub release API object, its assets array, or an array of {"name","size","digest"} objects.
Paste standard SHA-256 lines when the API does not provide asset digests.
Release verdict
A passing inventory proves only the declared artifact contract. It does not prove that installers run, signatures are valid, or software is secure.
Put the contract in CI for US$49.
FirstPass turns one public repository's supported-platform promise into a versioned contract and a blocking GitHub Actions preflight, then proves both a passing fixture and a deliberately broken release fixture.
- One public repository and one release workflow
- Platform, architecture, filename, checksum, and documentation-reference rules
- Machine-readable evidence artifact on every run
- Passing and failing fixtures plus exact acceptance checks
- One revision within seven days
Public intake first. Payment is requested only after fit and scope are confirmed. No repository write access or secrets are requested.