Safe operational metadata
Verified deliveries, without retaining raw payloads.
This view exposes the event contract and correlation result. Signatures are checked before parsing; payload bodies are not retained.
GitHubHMAC verifiedNormalizerfacts + keysRelease assemblerdeterministic evaluationPassport
Reading recent verified deliveries…
Retained
Delivery ID, event/action, repository, payload digest, signature result, processing duration, evidence IDs and release correlation.
Not retained
Raw request body, tokens, secrets, arbitrary PR descriptions, workflow logs or source code.