Live validated workflow
One release. One evidence path.
Follow a real Limen decision from pull request to historical public receipt.
Pull request
The proposed release enters the gate.
Policy is read from the trusted base revision. The proposed dependency state is evaluated from the pull request head.
GitHub / Dependency Review
Repository evidence names the change.
Repository context establishes the package, version, relationship and runtime scope before outside evidence is considered.
Telegraph / CVE_LOOKUP
Relevant CVEs take the routed evidence path.
Five real paid requests were made for this controlled workflow. The receipt exposes safe routing metadata, not payment credentials or private provider payloads.
CVE-2021-23337$0.01CVE-2026-4800$0.01CVE-2020-28500$0.01CVE-2025-13465$0.01CVE-2026-2950$0.01Limen policy
The repository rule sets the threshold.
The declared policy blocks high and critical findings in runtime scope. Uncertainty goes to REVIEW.
Decision engine
The same evidence produces explicit states.
Limen aggregates outcomes with the supported precedence HOLD > REVIEW > PASS. It does not silently choose one source when material evidence conflicts.
CVE-2021-23337HOLDCVE-2026-4800REVIEWCVE-2020-28500PASSCVE-2025-13465PASSCVE-2026-2950PASSGitHub result
The release check carries the consequence.
The real controlled workflow returned HOLD to GitHub. A blocking release is visible where the change is reviewed.
Open the real HOLD Action runHistorical public receipt
The decision leaves a receipt.
This historical public receipt is a sanitized projection of the durable evidence record. It is separate from the fresh P14 Judge Mode Action runs above.
Patched path
The same gate can pass a changed release.
A separate controlled run used Lodash 4.18.1 and returned PASS with no relevant decisions.
GitHub Action
kaelah971/limen-demo
- Package
- lodash@4.18.1
- Decision
- Evidence supports proceeding under policy.
- Relevant decisions
- 0
A PASS receipt was intentionally revoked during receipt lifecycle validation. It is not presented as active proof.
Validation checklist
One trace, with its limits visible.
- Real GitHub pull request evidence
- Real Dependency Review context
- Real paid Telegraph CVE_LOOKUP
- Separately validated x402 Base Sepolia settlement
- Deterministic policy evaluation
- Real HOLD GitHub result
- Durable hosted evidence ledger
- Public shareable receipt
- Receipt revocation lifecycle
This is controlled demo validation. It is not a claim of production adoption or external user usage.