Live validated workflow

One release. One evidence path.

Follow a real Limen decision from pull request to historical public receipt.

CVE_LOOKUPdemo / backfill
01

Pull request

The proposed release enters the gate.

Policy is read from the trusted base revision. The proposed dependency state is evaluated from the pull request head.

Repositorykaelah971/limen-demo
Pull request#1
Base SHA2f2cd0bbcffd00c562c82d834fe2669afc3352f7
HOLD head SHA84bda870ae3b90713f3d3a01a4b6a50f647d98c3
View source pull request
02

GitHub / Dependency Review

Repository evidence names the change.

Repository context establishes the package, version, relationship and runtime scope before outside evidence is considered.

Packagelodash
Installed4.17.20
Scoperuntime
Relationshipunknown
Manifestpackage-lock.json
CVECVE-2021-23337
03

Telegraph / CVE_LOOKUP

Relevant CVEs take the routed evidence path.

Five real paid requests were made for this controlled workflow. The receipt exposes safe routing metadata, not payment credentials or private provider payloads.

Requests5
Each request$0.01
Total cost$0.05
IntentCVE_LOOKUP
CVE-2021-23337$0.01
CVE-2026-4800$0.01
CVE-2020-28500$0.01
CVE-2025-13465$0.01
CVE-2026-2950$0.01
CVE-2021-23337 returned HIGH severity with CVSS Not available. Routed provenance: PREFLIGHT Infrastructure Signals, 1043 ms, Not available, x402 Not available.
04

Limen policy

The repository rule sets the threshold.

The declared policy blocks high and critical findings in runtime scope. Uncertainty goes to REVIEW.

Policy versionLP-fde4ac5cdba2
Block severitycritical, high
Dependency scoperuntime
UncertaintyREVIEW
05

Decision engine

The same evidence produces explicit states.

Limen aggregates outcomes with the supported precedence HOLD > REVIEW > PASS. It does not silently choose one source when material evidence conflicts.

CVE-2021-23337HOLD
CVE-2026-4800REVIEW
CVE-2020-28500PASS
CVE-2025-13465PASS
CVE-2026-2950PASS
CVE-2026-4800 shows GitHub HIGH and Telegraph CRITICAL. Result: REVIEW.
Overall result: HOLD. The primary condition is the affected runtime dependency matching a blocking policy rule.
06

GitHub result

The release check carries the consequence.

The real controlled workflow returned HOLD to GitHub. A blocking release is visible where the change is reviewed.

Open the real HOLD Action run
07

Historical public receipt

The decision leaves a receipt.

This historical public receipt is a sanitized projection of the durable evidence record. It is separate from the fresh P14 Judge Mode Action runs above.

ReceiptLM-REC-B1306724D0B84B6EBDDF7E36
Schemalimen.receipt.v1
Snapshot hash41cbf844690a2a15bf6d7d0fdc6bfd8bf8ae08cd684d735eb611d069f3ffebdf
Classificationdemo / backfill
Inspect the historical HOLD receipt

Patched path

The same gate can pass a changed release.

A separate controlled run used Lodash 4.18.1 and returned PASS with no relevant decisions.

GitHub Action

kaelah971/limen-demo

PASS
Package
lodash@4.18.1
Decision
Evidence supports proceeding under policy.
Relevant decisions
0
Telegraph requests0
Routing cost$0.00
Demo / backfill
Open the real PASS Action run

A PASS receipt was intentionally revoked during receipt lifecycle validation. It is not presented as active proof.

Validation checklist

One trace, with its limits visible.

  • Real GitHub pull request evidence
  • Real Dependency Review context
  • Real paid Telegraph CVE_LOOKUP
  • Separately validated x402 Base Sepolia settlement
  • Deterministic policy evaluation
  • Real HOLD GitHub result
  • Durable hosted evidence ledger
  • Public shareable receipt
  • Receipt revocation lifecycle

This is controlled demo validation. It is not a claim of production adoption or external user usage.