metadata: id: audit-log-bad-digest type: AuditLog gemara-version: "1.1.0" version: "1.0.0" description: "Invalid audit log: evidence source digest uses uppercase algorithm" author: id: lead-auditor name: "Auditor" type: Human mapping-references: - id: github-api title: "GitHub Dependency Graph API" version: "2026" url: "https://docs.github.com/en/rest/dependency-graph" target: id: gemara-repo name: "gemaraproj/gemara" type: Software uri: "https://github.com/gemaraproj/gemara" environment: production owner: responsible: - name: "Auditor" affiliation: "External Audit Firm" accountable: - name: "Project Lead" affiliation: "OpenSSF" summary: "Digest format validation test." criteria: - reference-id: github-api results: - id: AR-QA-01 title: "Dependency manifests present" type: Observation description: "Repository includes dependency manifests." criteria-reference: reference-id: github-api entries: - reference-id: OSPS-QA-02 evidence: - id: EV-QA-01 type: api-response description: "Dependency manifests from the GitHub dependency graph SBOM endpoint" collected-at: "2026-02-10T15:05:00Z" source: reference-id: github-api coordinate: "/repos/gemaraproj/gemara/dependency-graph/sbom" digest: "SHA256:invalidbecauseuppercasealgorithm"