Sigstore Verification

MLB Picks · Saturday, July 4, 2026

The Sigstore log entry below cryptographically proves that the picks file existed at a specific moment in time. The hash in Sigstore matches the SHA-256 of the picks file — meaning the file cannot have been altered since the log entry was created.

What was signed

File
mlb/5 picks · 2026-07-04.json
SHA-256
fbf4aebd0dcae8a2a09ad578df58e45db7f0d445b8a5eefac9313f1d5c0138c2

Contents — 5 picks

  • ·MINMINNYYNYYUnder 10.0 @ 1.88
  • ·SDSDLADLADSD ML @ 3.20
  • ·TBTBHOUHOUTB -1.5 @ 2.56
  • ·NYMNYMATLATLUnder 8.0 @ 1.95
  • ·DETDETTEXTEXUnder 8.0 @ 1.88
hashes match

What Sigstore logged

SHA-256 of signed content
fbf4aebd0dcae8a2a09ad578df58e45db7f0d445b8a5eefac9313f1d5c0138c2
Integrated at (Rekor log time)
2026-07-04 13:33:03 UTC
Log index
#2,070,946,481
Signed by
github.com/jvalenza11/dailybet
.github/workflows/daily_pipeline.yml@main
See the original entry on search.sigstore.dev

What this proves, in plain English

Sigstore is a third-party transparency log. When our pipeline ran at 2026-07-04 13:33:03 UTC, it computed the SHA-256 of the picks file and submitted that hash to Sigstore. Sigstore recorded it, then notarized the entry with the GitHub Actions identity that submitted it (visible above). The entry can never be deleted or backdated.

If we changed even one character of the picks file after this entry was created, its SHA-256 would change — and the file no longer matches the hash Sigstore has on record. That's the chain: file → hash → Sigstore log entry → identity. Anyone can independently re-compute the SHA of the picks file above and confirm it matches the hash shown on this page and on search.sigstore.dev.

← Back to the full proof page