Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“In my opinion, two packages would not have been necessary.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0bd121d4d2f006c46c1f59899220171c901bce0c92c681da8ccd419c7c54128f
Signature (Ed25519, base64)
KMBUzo3dyjQEp7aaUOFavwi810a0++wiKegPeYQ8maGX2FK8ANF6SXlaOnE2LxagQqendqv+nknqBZwSs5QUCQ==
Merkle root
8a6ad893af0f0bb6c448016a777af61f3f4935afd82df0db132e64f813535715
Merkle path
["0bd289ae70c467109332101befbeacb57813c68b7a07ee014490bba942af7a7e","8dcf96dd474841b91da669e87dc8fe2f825e62aff40950d7b8b97e00a852dda6","aeb6e4ef0912e1997bcf84aa286198476d7a92b34b397f8228b35b0e4ac02f35","4fc9505d0e724a5b327b9c1bfa49af0b1e92872562d9773161e2d51748e7663e","a3bf6158e32f4222995110c5f1b92217d1821c78f78be3113c8afd6638897564","f860301bed36e832811d990115d6952eab3b5507bf6172452d6ff5e8a3917e0e","430fd993ba5be704033244849ff5471c428c30a419054141d9ea39a965ed18c6","3d07c283cdf8836de2013b74d14396d7b2a008a581ea0cfa63a2fc5b6ea762ef","f6ed41cf6fbe5e4c8369b28b6d3e5f92eeb0be6ef7515976dbb9cb6d24959669","5ef390b2e65a59a6234f645dacfe5ef14f380726778aec05bfd44db5ed73c35b","7a7d91c8e4029a3c6ebecfdfc59094e88df03910b5abd1afa5cfc2f551bab65a","315a2754803b75c9628a55a4cabfb74de1b5b61bd2dfb993d59bd76faec82e97","5583124fe582e6d7b0315186ecf512c5208dfdd6f55f448bd7355fb580296e0a","6276ae8d472cde22fe3044fd8f103b6cd700eb8d1fe29c2f968f62a699dc326d","8834edd87c11ce9424175f1744f71345038aee1c5b6f350a6f7bc2a49b63e8e9"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2515144749 · entry 108e9186e8c5677a63b7…
Expected log hash
b6b79ad662332330e69c4ef135f6fb13ddc70048f846024d496aaa533f7f7fc0 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787137589246","kind":"published-quote","locale":"en","page":"theme:ifolor/packaging/en","quote":"In my opinion, two packages would not have been necessary.","rating":4,"review_date":"2026-04-07","source":"Trusted Shops","source_url":"https://www.trustedshops.ch/bewertung/info_X309A43086E7145E358EE1687E9DF7162.html","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (8a6ad893af0f…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.