{
  "schema_version": "1.0.0",
  "snapshot_date": "2026-10-02",
  "publication_state": "owner_reviewed",
  "statuses": {
    "in_progress": {
      "label": "In progress",
      "description": "A review is underway. No completed proof or runtime result is claimed."
    },
    "model_only": {
      "label": "Model only",
      "description": "A theorem covers the stated mathematical model. This status does not establish correspondence with the deployed software."
    },
    "runtime_checked": {
      "label": "Runtime checked",
      "description": "Identified outputs passed the stated checks. The result applies to those runs; it is not a universal implementation proof."
    },
    "refinement_proved": {
      "label": "Refinement proved",
      "description": "A proof connects the identified implementation to the stated specification. Assumptions and the execution trust boundary still apply."
    }
  },
  "entries": [
    {
      "id": "deseq2-normalization",
      "revision": 3,
      "software": "DESeq2",
      "kind": "existing_software",
      "area": "Normalization",
      "title": "Translated-model proof with finite numerical-consistency certificates",
      "status": "model_only",
      "lifecycle": "active",
      "review_date": "2026-10-02",
      "review_basis": "Independent mathematical review reported 10 passed checks at the pinned contribution commit. Reviewed source hashes match this catalog. The full contribution gate was replayed separately in an isolated copy.",
      "version": {
        "label": "1.52.0 · 16aeab6d6158bd8cbb8e98764c2f33399b1a3fd3",
        "identity_state": "pinned",
        "hash_algorithm": "sha256",
        "hash": "8c91699286336350e66eec132ce6fdf5bb4af78e2a4d015a5a61224f62a95984",
        "hash_scope": "Official DESeq2_1.52.0.tar.gz archive. R/core.R and the repository commit are pinned separately in sources.json."
      },
      "official_source": {
        "kind": "official_upstream",
        "label": "Bioconductor DESeq2",
        "url": "https://bioconductor.org/packages/3.23/bioc/html/DESeq2.html",
        "pinned_url": "https://bioconductor.org/packages/3.23/bioc/src/contrib/DESeq2_1.52.0.tar.gz"
      },
      "property": {
        "state": "established_model",
        "summary": "In the real-valued translation, positive sample scaling preserves the retained rows and normalized between-sample ratios. Size factors follow a proved scaling identity.",
        "formal_statement": "The exact-real estimator is exp(median(log ratios)); even medians average central log values. For positive scales c and nonempty all-positive retained rows, s(K scaled by c)[j] = (c[j] / G(c)) * s(K)[j], where G(c) = exp(mean(log(c)))."
      },
      "assumptions": [
        "The mathematical model has finite real-valued count rows, positive sample scales and at least one row positive in every sample.",
        "The target uses the default ratio method and stats::median; even medians average the central log values.",
        "The production interpretation uses dense nonnegative counts, at least one sample and one all-positive row, without missing or nonfinite values.",
        "R execution, binary-output recording and Python decoding faithfully represent the executed function and observed values."
      ],
      "exclusions": [
        "A chosen 10^-12 tolerance checks recorded-output consistency. It does not prove accuracy against the ideal estimator or R/libm refinement.",
        "No formal R refinement, universal floating-point accuracy bound, full-package verification or statistical validity claim.",
        "No poscounts, supplied geoMeans, custom location functions, control-gene indexing or other DESeq2 routines.",
        "Execution used the unchanged upstream function assignment with dependencies; the full package namespace/S4 route was not tested or proved."
      ],
      "proof_artifact": {
        "state": "available",
        "summary": "Lean 4.32.2 and pinned Mathlib prove invariants of exp(median(log ratios)), including even-row log medians. An independent mathematical review passed 10 scope and theorem checks.",
        "artifacts": [
          {
            "label": "Normalization.lean",
            "href": "evidence/deseq2/Normalization.lean",
            "sha256": "4206ed6b251d3d43e11e9af77496d1bdeb9c32847a2fb8531ef44899658469ee"
          },
          {
            "label": "ProductionCertificates.lean",
            "href": "evidence/deseq2/ProductionCertificates.lean",
            "sha256": "d011ba3a2bcebff4eba612c32178a6189997011421dde44284be1411fe172129"
          },
          {
            "label": "axioms.txt",
            "href": "evidence/deseq2/axioms.txt",
            "sha256": "f522e3cae9717bb0e7e57b279751e1177deb3217b5238cb2dc4a1e11b7e7bf0f"
          },
          {
            "label": "certificate-check.txt",
            "href": "evidence/deseq2/certificate-check.txt",
            "sha256": "ad9b82d826d2485cc1f59aaa4a2980c828bdfa43ebd5fdbccdcf840942d5469e"
          },
          {
            "label": "lake-manifest.json",
            "href": "evidence/deseq2/lake-manifest.json",
            "sha256": "36e34686885812ae5099114347f4c49019a347221cc13765e0dbf174a1261d18"
          },
          {
            "label": "lakefile.toml",
            "href": "evidence/deseq2/lakefile.toml",
            "sha256": "5ec19a32073e4ee43b4582b22ac9157841add3fe5222c0ac0b3f4a3bd6d7c2a4"
          },
          {
            "label": "lean-toolchain",
            "href": "evidence/deseq2/lean-toolchain",
            "sha256": "2bdc48adfa58d0017e538a0ad117c5d73d35deec879978f909406a80c8037273"
          },
          {
            "label": "Independent mathematical review",
            "href": "evidence/deseq2/review-assessment.json",
            "sha256": "215263ae09a4472b07bd11b870728796ca5906327c8501d9da52c6b59cb31932"
          }
        ],
        "declarations": [
          "DESeq2Verification.estimateRatio_scale",
          "DESeq2Verification.normalized_ratio_scaled",
          "DESeq2Verification.retained_scale",
          "DESeq2Verification.sizeFactor_global_scale",
          "DESeq2Verification.checkRelative_sound"
        ]
      },
      "runtime_evidence": {
        "state": "available",
        "summary": "The unchanged function assignment ran on 10 synthetic matrices. The 59 kernel-checked comparisons satisfy a chosen 10^-12 tolerance, not a proved numerical error bound or accuracy guarantee against the ideal estimator. The largest observed residual is about 3.7e-15.",
        "artifacts": [
          {
            "label": "certificates.json",
            "href": "evidence/deseq2/certificates.json",
            "sha256": "aed417f09efd35a6d9b733bdad2b3bab13fee02d1c95cf7121728ea513e99f46"
          },
          {
            "label": "cases.tsv",
            "href": "evidence/deseq2/cases.tsv",
            "sha256": "557f6a81fb9f095c7eb0db4685b9d81f4279fce4b92f4f33346bb8df25605553"
          },
          {
            "label": "boundaries.tsv",
            "href": "evidence/deseq2/boundaries.tsv",
            "sha256": "852124914c66d241dee55f41ba245d3378784711e4617beb31863b679ed20f11"
          },
          {
            "label": "repeatability.json",
            "href": "evidence/deseq2/repeatability.json",
            "sha256": "003af1d5ccd5bd6acfc3c49218c228475bf1b45ae94da5b1622d7b06b9698b6f"
          },
          {
            "label": "sources.json",
            "href": "evidence/deseq2/sources.json",
            "sha256": "853fbcb116de8479204fd818bd5bf5ad4edb35d225d25e6f5fa91823f8a8235e"
          }
        ]
      },
      "execution_bridge": {
        "state": "not_established",
        "summary": "R/libm floating-point correspondence remains unproved. Exact rational certificates compare recorded outputs, not output accuracy against the ideal estimator. The unchanged upstream function assignment ran with dependencies; the full package namespace/S4 route was not exercised.",
        "artifacts": [
          {
            "label": "bridge.R",
            "href": "evidence/deseq2/bridge.R",
            "sha256": "f2911fb5efedeeb7569cfd42bfba717a031bf65cf0cc691aad378904d794f41d"
          },
          {
            "label": "certify.py",
            "href": "evidence/deseq2/certify.py",
            "sha256": "c563c74d2b1337c6cdd0d022a3fe503b1d64c4db83dcfb78fd6b3888e4766b33"
          }
        ]
      },
      "trusted_base": [
        "Lean 4.32.2 kernel, pinned Mathlib and axioms propext, Classical.choice and Quot.sound.",
        "Source/hash checks, unchanged R function execution, R/libm, binary-output recording and Python binary64 decoding.",
        "The connection from the intended algorithm to the real-valued translation; no proof of numerical implementation correspondence."
      ],
      "next_step": "Establish accuracy against the ideal estimator and production floating-point correspondence before considering an implementation-refinement claim.",
      "history": [
        {
          "date": "2026-10-02",
          "revision": 1,
          "action": "created",
          "reason": "Review target recorded; results remain in progress."
        },
        {
          "date": "2026-10-02",
          "revision": 2,
          "action": "corrected",
          "reason": "Accepted translated-model invariants and finite production-output comparisons after a copied gate rerun. Kept the main claim at model-only assurance.",
          "previous_record": {
            "label": "Previous record · revision 1",
            "href": "history/deseq2-normalization/revision-1.json",
            "sha256": "5dda1617235c1dbca239b86215769f39b64d4b717554bb31198791e4a4a1c8c5"
          }
        },
        {
          "date": "2026-10-02",
          "revision": 3,
          "action": "corrected",
          "reason": "Attached the passed independent mathematical review. Retained model-only status and clarified that consistency certificates do not establish ideal-estimator accuracy.",
          "previous_record": {
            "label": "Previous record · revision 2",
            "href": "history/deseq2-normalization/revision-2.json",
            "sha256": "402d2fcc2df74949b6342b8288a10344b3b14ab373922ce5970d1263ba531f4d"
          }
        }
      ],
      "withdrawal": null,
      "execution_environment": {
        "api": "estimateSizeFactorsForMatrix(..., type=\"ratio\", locfunc=stats::median)",
        "orientation": "Count rows by sample columns",
        "backends": [
          "Dense nonnegative count matrix; unchanged upstream function assignment evaluated from R/core.R. No full DESeq2 package installation."
        ],
        "packages": {
          "DESeq2 source": "1.52.0",
          "R": "4.6.1",
          "MatrixGenerics": "1.24.0",
          "matrixStats": "1.5.0",
          "Lean": "4.32.2"
        },
        "upstream_commits": {
          "DESeq2": "16aeab6d6158bd8cbb8e98764c2f33399b1a3fd3",
          "Mathlib": "905b95818eb32af7874a58b427f50c1711a5e96c"
        },
        "configuration": {
          "method": "ratio",
          "location": "stats::median",
          "recorded_output": "binary64",
          "chosen_comparison_tolerance": "1/1000000000000"
        },
        "bounds": [
          "At least one sample and one row positive in every sample; missing and nonfinite values are excluded.",
          "Demonstrated integer inputs and their scaled values remain below 2^53.",
          "Finite evidence covers 59 nontrivial comparisons across 10 synthetic matrices; 31 residuals are nonzero.",
          "The checker rejects a 1% altered output and a zero reference denominator."
        ]
      }
    },
    {
      "id": "scanpy-aggregation",
      "revision": 3,
      "software": "Scanpy",
      "kind": "existing_software",
      "area": "Aggregation",
      "title": "Grouped-count sums · proved output checker",
      "status": "runtime_checked",
      "lifecycle": "active",
      "review_date": "2026-10-02",
      "review_basis": "Independent mathematical review reported 10 passed checks at the pinned contribution commit. Both reviewed proof source hashes match this catalog. Module compilation and replay passed; that review did not rerun Scanpy or rebuild the imported dependency environment. The contribution gate was replayed separately in an isolated copy.",
      "version": {
        "label": "1.12.4 · ff2133115f639fccce9633aa7f5309c36a0972e7",
        "identity_state": "pinned",
        "hash_algorithm": "sha256",
        "hash": "44462822c465c704ff1526ea7af97b39894c26879463677a6eb0da8d1732c67d",
        "hash_scope": "src/scanpy/get/_aggregated.py at the recorded official Scanpy commit. Full package, dependency and inspected-file pins are in pins.json."
      },
      "official_source": {
        "kind": "official_upstream",
        "label": "scverse / Scanpy",
        "url": "https://github.com/scverse/scanpy",
        "pinned_url": "https://github.com/scverse/scanpy/blob/ff2133115f639fccce9633aa7f5309c36a0972e7/src/scanpy/get/_aggregated.py"
      },
      "property": {
        "state": "observed_runtime",
        "summary": "A proved checker accepted outputs from 41 actual Scanpy runs on synthetic count matrices. It checked grouped sums, labels and supplied source witnesses.",
        "formal_statement": "ScanpyAggregate.check_sound proves the stated contract for accepted serialized input/output pairs. This checks observed outputs; it does not refine the original Scanpy implementation."
      },
      "assumptions": [
        "Python faithfully extracts and serializes the actual input and output, and decodes observed binary64 values with as_integer_ratio.",
        "Source-index/name witnesses are adapter-supplied. Scanpy does not return them; Lean checks them against the serialized input.",
        "The pinned packages, JIT configuration and runtime load correctly. The execution environment remains trusted.",
        "The declared input domain, group ordering, labels and Boolean mask match the actual call."
      ],
      "exclusions": [
        "No Scanpy implementation refinement. Python extraction and adapter-supplied source witnesses remain trusted.",
        "No Python, Numba, SciPy or AnnData refinement; no IEEE-754 reduction proof.",
        "No other reducers or axes, multiple group columns, negative/general floating inputs, layers, GPU, Dask or backed data.",
        "No whole-package correctness, statistical calibration, biological validity or upstream endorsement."
      ],
      "proof_artifact": {
        "state": "available",
        "summary": "A general Lean-proved output checker establishes sum, identity, coverage and bound properties. Fourteen corrupted or unsupported transcripts have kernel-proved rejections. Independent mathematical review passed 10 checks; original Scanpy implementation refinement remains unproved.",
        "artifacts": [
          {
            "label": "ScanpyAggregate.lean",
            "href": "evidence/scanpy/ScanpyAggregate.lean",
            "sha256": "6370f25f8e4eee9e2aa1c859582c1b944658c2a605e22a5edfa4976523843a81"
          },
          {
            "label": "Observed.lean",
            "href": "evidence/scanpy/Observed.lean",
            "sha256": "0070878c71b7b1baf8fa3630d03b0d37c83527c7aa3f4000b289c30f45742968"
          },
          {
            "label": "general-kernel.log",
            "href": "evidence/scanpy/general-kernel.log",
            "sha256": "0b9113dce457abd1dbd68a2a7463fc5d685025b1192804a71050fe7b75e97e78"
          },
          {
            "label": "observed-kernel.log",
            "href": "evidence/scanpy/observed-kernel.log",
            "sha256": "28da0ac87c3151b0188145ddba9bcc74207718c751cdb2fc60dc243372f44bb4"
          },
          {
            "label": "lean-toolchain",
            "href": "evidence/scanpy/lean-toolchain",
            "sha256": "d5edba4e4b8faad9c1baeadb265716d20d03be4d1a2647dc5e35b0c0325bea7b"
          },
          {
            "label": "lakefile.toml",
            "href": "evidence/scanpy/lakefile.toml",
            "sha256": "b71720314674ddce750ead08142aacd1ff821c2bcebb4c3327580c219ae19383"
          },
          {
            "label": "lake-manifest.json",
            "href": "evidence/scanpy/lake-manifest.json",
            "sha256": "037dc12d2899a24fc027fba97a88068c9cdb07189bb8b2d1e217973e8ee1ca10"
          },
          {
            "label": "Independent mathematical review",
            "href": "evidence/scanpy/review-assessment.json",
            "sha256": "75a391132399f8234a61f555def2b186187921377ab286c7d1fac738ad06e129"
          }
        ],
        "declarations": [
          "ScanpyAggregate.check_sound",
          "ScanpyAggregate.filtered_sum_eq",
          "ScanpyAggregate.accepted_group_identity",
          "ScanpyAggregate.accepted_source_identity",
          "ScanpyAggregate.accepted_feature_identity",
          "ScanpyAggregate.accepted_group_coverage",
          "ScanpyAggregate.accepted_sum_bound",
          "ScanpyAggregate.bounded_prefix_no_wrap",
          "ScanpyAggregate.bounded_wordSum_exact"
        ]
      },
      "runtime_evidence": {
        "state": "available",
        "summary": "41 actual Scanpy executions on synthetic matrices passed the proved checker across dense, CSR and CSC backends. The copied contribution gate reproduced all seven deterministic artifacts.",
        "artifacts": [
          {
            "label": "results.json",
            "href": "evidence/scanpy/results.json",
            "sha256": "8ea6d5ae6452012cb092457db084c4924c070f5f09e5f0094cb28739fec928e6"
          },
          {
            "label": "cases.json",
            "href": "evidence/scanpy/cases.json",
            "sha256": "e1022ca51113506968807f5bec7a963b60ff9f0ca36909a2ce4fb2c6b0ca6e7a"
          },
          {
            "label": "pins.json",
            "href": "evidence/scanpy/pins.json",
            "sha256": "bac08a8f81e5df0282a3d206249c2813fb766c60c953ccfa10cf22eeba985f9a"
          },
          {
            "label": "runtime-backends.json",
            "href": "evidence/scanpy/runtime-backends.json",
            "sha256": "c43dc46ac9ec130dc2e1bd31edfcdde17c4878ab9467853cec5a9e6134f1afc9"
          },
          {
            "label": "limit-probes.json",
            "href": "evidence/scanpy/limit-probes.json",
            "sha256": "7f02e24c75f2c96a852d13c92efb722e4db45a43d4beab26ea2dec229881948b"
          },
          {
            "label": "catalog-entry.json",
            "href": "evidence/scanpy/catalog-entry.json",
            "sha256": "887a86c0192f0d92b6dbe38664abb2a76ac6cd05ebdac09e8220a5822dba5d5f"
          },
          {
            "label": "uv.lock",
            "href": "evidence/scanpy/uv.lock",
            "sha256": "ac31930d86faf4e8fa2308b746c59fa002b41c0f96648590a104606d243565b5"
          }
        ]
      },
      "execution_bridge": {
        "state": "runtime_observed",
        "summary": "Python extraction, serialization and binary64 decoding are trusted. Source-index/name witnesses are adapter-supplied, not returned by Scanpy. Lean checks these witnesses against the serialized input; it does not establish their origin in execution.",
        "artifacts": [
          {
            "label": "bridge.py",
            "href": "evidence/scanpy/bridge.py",
            "sha256": "f47b9c942cad96188ae2825047f04dfce8eb199a94a36af4458dd0fed3f3d0a4"
          }
        ]
      },
      "trusted_base": [
        "Lean 4.34.1 kernel and standard logical foundations: propext and Quot.sound.",
        "Python, package loading, AnnData input/output extraction, as_integer_ratio binary64 decoding and serialization.",
        "Adapter-supplied source witnesses and their correspondence with the executed data; the compiler/JIT, runtime and operating system."
      ],
      "next_step": "Establish execution correspondence before considering any implementation-refinement claim. Python extraction, serialization, binary64 decoding and adapter-supplied source witnesses remain trusted.",
      "history": [
        {
          "date": "2026-10-02",
          "revision": 1,
          "action": "created",
          "reason": "Review target recorded; results remain in progress."
        },
        {
          "date": "2026-10-02",
          "revision": 2,
          "action": "corrected",
          "reason": "Accepted the completed proved-output-checker contribution after an isolated full gate rerun; status describes runtime output checks, not Scanpy refinement.",
          "previous_record": {
            "label": "Previous record · revision 1",
            "href": "history/scanpy-aggregation/revision-1.json",
            "sha256": "a518a8d0a2bbc2c35bbbad325a3a39a4e8c439d3b4c3b922718142ef98f2d97c"
          }
        },
        {
          "date": "2026-10-02",
          "revision": 3,
          "action": "corrected",
          "reason": "Attached the passed independent mathematical review after matching both proof sources. Retained runtime-checked status and explicit trusted adapter/source-witness boundaries.",
          "previous_record": {
            "label": "Previous record · revision 2",
            "href": "history/scanpy-aggregation/revision-2.json",
            "sha256": "11e300338bca9e509b0c27856ed8e4eebd76c6646adcd0ea4721afb5f200ca83"
          }
        }
      ],
      "withdrawal": null,
      "execution_environment": {
        "api": "scanpy.get.aggregate(adata, by='group', func='sum', axis='obs', mask='keep')",
        "orientation": "observations by features",
        "backends": [
          "numpy.ndarray int64 -> float64",
          "scipy.sparse.csr_matrix int64 -> int64",
          "scipy.sparse.csc_matrix int64 -> int64"
        ],
        "packages": {
          "Python": "3.13.15",
          "Lean": "4.34.1",
          "anndata": "0.13.4",
          "fast-array-utils": "1.5.1",
          "llvmlite": "0.50.0",
          "numba": "0.68.0",
          "numpy": "2.5.3",
          "pandas": "3.0.6",
          "scanpy": "1.12.4",
          "scipy": "1.18.1"
        },
        "upstream_commits": {
          "anndata": "a487b81d38d4bfe7c7d76f01eed72a8622665c65",
          "scanpy": "ff2133115f639fccce9633aa7f5309c36a0972e7"
        },
        "configuration": {
          "disable_jit": 0,
          "threading_layer": "workqueue",
          "threads": 2
        },
        "bounds": [
          "Nonempty observations and features, with at least one assigned category; observations are rows and features are columns.",
          "One categorical group column with explicit order and a Boolean inclusion mask.",
          "Nonnegative int64 counts; each entry and selected group/feature sum is at most 2^53 (9,007,199,254,740,992).",
          "Canonical sparse storage with unique indices; explicit and implicit zeros are allowed.",
          "Unique, nonempty printable ASCII labels. Missing assignments are excluded; unused categories are removed.",
          "Observed groups whose members are all masked remain with zero counts and sums."
        ]
      }
    },
    {
      "id": "veriformatics-holm-finite",
      "revision": 1,
      "software": "Veriformatics Holm component",
      "kind": "own_component",
      "area": "Multiple testing",
      "title": "Finite-model family-wise error bound",
      "status": "model_only",
      "lifecycle": "active",
      "review_date": "2026-10-02",
      "review_basis": "Local mathematical proof snapshot and review record inspected. This is not an external software certification or an independent audit of this catalog.",
      "version": {
        "label": "0.1.0 · frozen mathematical source",
        "identity_state": "pinned",
        "hash_algorithm": "sha256",
        "hash": "eb6eb8b1801db92dc1213287b739bd4659a360f005745fa698af9ce8af1cd0c0",
        "hash_scope": "Bridge.lean in the retained proof snapshot. Every supporting source file has a separate artifact hash."
      },
      "official_source": {
        "kind": "authoring_snapshot",
        "label": "Veriformatics source snapshot",
        "url": "evidence/holm/Bridge.lean",
        "pinned_url": "evidence/holm/Bridge.lean"
      },
      "property": {
        "state": "established_model",
        "summary": "In a finite rational probability model, the chance of any reported false rejection is at most the fixed alpha, under the listed premises.",
        "formal_statement": "HolmStat.checked_reporting_fwer bounds the unconditional accepted-and-false-rejection event for the frozen exact Holm formula. It does not bound error conditional on acceptance."
      },
      "assumptions": [
        "A finite probability law has nonnegative rational weights that sum to one, with represented rational p-values.",
        "The hypothesis family, true-null subset and alpha are fixed across outcomes.",
        "Each true-null p-value meets the stated marginal validity bound. Independence is not required.",
        "Only checker-accepted decisions are reported; failed checks report no rejections."
      ],
      "exclusions": [
        "This is Veriformatics’ own component. It does not verify R stats::p.adjust, DESeq2 or Scanpy.",
        "No proof of real-data p-value validity, selection practice, biological truth or arbitrary continuous probability laws.",
        "No native compiler, parser, R/Python adapter or deployed execution correspondence is proved here."
      ],
      "proof_artifact": {
        "state": "available",
        "summary": "The retained Lean 4.34.1 sources rebuilt locally. All 24 audited declarations use only the listed standard axioms. The build record is unsigned.",
        "artifacts": [
          {
            "label": "Conditional.lean",
            "href": "evidence/holm/Conditional.lean",
            "sha256": "dd981dde8a8ca1cf83013a3670b96e72aaeddee06e8fcc797a76c854094c7c55"
          },
          {
            "label": "Bridge.lean",
            "href": "evidence/holm/Bridge.lean",
            "sha256": "eb6eb8b1801db92dc1213287b739bd4659a360f005745fa698af9ce8af1cd0c0"
          },
          {
            "label": "FrozenPrototype.lean",
            "href": "evidence/holm/FrozenPrototype.lean",
            "sha256": "3ac9e49a4735514e483ab359445efa3c379912acadb2e9643fb79b50d059df5c"
          },
          {
            "label": "Examples.lean",
            "href": "evidence/holm/Examples.lean",
            "sha256": "84a132635f55ad6b9adf4e1207e84a5764170ef2cd74ca04f2f443865c56f027"
          },
          {
            "label": "Audit.lean",
            "href": "evidence/holm/Audit.lean",
            "sha256": "4763e1b471a08cda6cb7732c954cee4e99f22adc8bcd489f3ca84d8f60096c06"
          },
          {
            "label": "lakefile.toml",
            "href": "evidence/holm/lakefile.toml",
            "sha256": "2d3bb02f236652d29ac7b05b18a0fa121ef8d8fd019c203bc668f38c91f2b514"
          },
          {
            "label": "lake-manifest.json",
            "href": "evidence/holm/lake-manifest.json",
            "sha256": "a8be097ea7ff5cc65686eeb436627ac513ffcb042a8fcb72f9da590c3e980747"
          },
          {
            "label": "lean-toolchain",
            "href": "evidence/holm/lean-toolchain",
            "sha256": "d5edba4e4b8faad9c1baeadb265716d20d03be4d1a2647dc5e35b0c0325bea7b"
          },
          {
            "label": "CONTRACT.md",
            "href": "evidence/holm/CONTRACT.md",
            "sha256": "4e8f0cba2d8f3379e0bc3d2f76d842ae1eaa64ab2fea32a77be9172aa532b5a9"
          },
          {
            "label": "local-check.json",
            "href": "evidence/holm/local-check.json",
            "sha256": "b10ff417a5aec29615ee9c9fcb6165e7f96e3671bdc58d144f6106814145663d"
          }
        ],
        "declarations": [
          "HolmStat.finite_holm_fwer",
          "HolmStat.frozen_formula_eq",
          "HolmStat.checked_reporting_fwer"
        ]
      },
      "runtime_evidence": {
        "state": "not_established",
        "summary": "No claim about an actual R or bioinformatics package execution is made by this entry.",
        "artifacts": []
      },
      "execution_bridge": {
        "state": "model_internal_only",
        "summary": "Formal equality connects the theorem to the frozen pure Lean formula and checker. A deployed software refinement is not established.",
        "artifacts": [
          {
            "label": "Bridge.lean",
            "href": "evidence/holm/Bridge.lean",
            "sha256": "eb6eb8b1801db92dc1213287b739bd4659a360f005745fa698af9ce8af1cd0c0"
          }
        ]
      },
      "trusted_base": [
        "Lean 4.34.1 kernel and standard library; axioms propext, Classical.choice and Quot.sound.",
        "The written specification and its interpretation as the intended statistical question.",
        "Any deployed use would additionally trust the unproved compiler, parser, adapters, runtime and operating system."
      ],
      "next_step": "Review execution correspondence and applicability of the statistical premises before applying this theorem to a workflow.",
      "history": [
        {
          "date": "2026-10-02",
          "revision": 1,
          "action": "created",
          "reason": "Own mathematical component recorded separately from third-party package reviews."
        }
      ],
      "withdrawal": null,
      "execution_environment": null
    }
  ]
}
