From Pull Requests to Reproducible Interoperability: Building an Evidence-First Contributor Network
Open source collaboration becomes much more useful when contribution history is not just a list of usernames and merged pull requests, but a network of reproducible technical evidence.
At MyZubster, we have been working on a contributor model where public work can be connected to:
- exact pull requests;
- canonical merge commits;
- independent test checkpoints;
- external contributor-owned repositories;
- bounded interoperability experiments;
- explicit limitations on what each test actually proves.
The goal is simple:
PUBLIC CONTRIBUTION
↓
EXACT SOURCE / COMMIT
↓
REPRODUCIBLE TEST
↓
PUBLIC EVIDENCE
↓
BOUNDED TESTED STATUS
Not every contributor needs to work inside the same repository.
Some contributors maintain their own projects, forks, research packages or independent runtime environments. Instead of absorbing those projects into MyZubster, we can build small, reproducible bridges between independently owned work.
Current tested contributor checkpoints
Nicola / N4K48
GitHub:
- @nicolaususnicola-lgtm
- External project: nicolaususnicola-lgtm/myzubster-mvp
Nicola's work became one of our first runtime interoperability experiments.
The bounded test used:
MyZubster VPS
↓
authenticated HTTPS broker
↓
contributor-controlled N4K48 agent
↓
local contributor catalog
↓
bounded result returned to MyZubster
The participant-controlled environment successfully returned the expected result to the bridge.
Evidence state:
TESTED
Canonical MyZubster evidence merge:
0c00836a96b36d7c64de098dd26d39ac5ddaf98a
Nicola also authored MyZubster PR #1460, merged at:
ee8c15d4b26824b75345c2eebc62ac034058b84a
This checkpoint demonstrates a bounded runtime bridge.
It does not by itself establish complete decentralization, direct P2P networking, security certification, employment, payment or governance authority.
Shweta-singh24 / MyZubsterGateway
GitHub:
- @Shweta-singh24
- External project: Shweta-singh24/MyZubsterGateway
Shweta's external MyZubsterGateway work provided a good opportunity to test something different: can we independently reproduce a security/policy checkpoint from an external repository without pretending that the code has been deployed or merged upstream?
We pinned the verifier to this exact source commit:
82461433e0c5bfee9aa369b4a71e9331261cf803
The upstream MyZubsterGateway PR #1385 is:
CLOSED_UNMERGED
Our independent VPS verifier reproduced:
verifier status: TESTED
policy checks: 14/14 PASS
syntax checks: 5/5 PASS
wiring checks: 6/6 true
The wiring checkpoint covered bounded Tari/XMR jurisdictionGate paths.
The MyZubster evidence PR #1575 passed:
- CI – Test e Lint
- Security Audit
- MYZ-164 Seller Free policy
- Continuous Evidence Gate
and was squash-merged at:
dc4fb1e3c403f6e554c2402ec9fb4c5dfd93e593
This means we independently reproduced that exact checkpoint.
It does not mean the upstream PR was merged, the system was deployed to production, legal compliance was certified or a security certification was issued.
That distinction matters.
Open Period Care / khongten124
GitHub:
- @khongten124
- External project: khongten124/myzubster
Open Period Care is an example of a different type of interoperability.
Instead of a runtime security or API bridge, this work connects:
PUBLIC RESEARCH
↓
EVIDENCE PACKAGE
↓
KNOWLEDGE CARDS
↓
STRUCTURED RETRIEVAL
↓
CIRCULAR CARE / KNOWLEDGE GRAPH
The contributor's research package focuses on areas including materials, sustainable health technologies, technical documentation and evidence analysis.
Relevant MyZubster contribution anchors:
PR #1451:
fc4a5cd30c854a242e6ed39e757c77f463c5d231
PR #1489:
6d88448821f25a252a79a777101ef904af8bbccb
The contributor-scoped semantic bridge has been recorded as:
TESTED
This checkpoint is about evidence normalization, provenance and retrieval.
It does not establish a medical credential, professional certification, physical recycling proof or production blockchain implementation.
More tested contributions inside MyZubster
Not every tested contributor checkpoint comes from an external repository.
Several contributors have testable work directly inside the canonical MyZubster repository.
Aming9303 — signed payment webhooks
GitHub:
PR #891 implemented signed lifecycle webhooks.
Canonical merge:
be78e0cf9081c3346aa0c61e022acd297d745619
Independent regression testing covered:
- HMAC-SHA256 signing;
- stable delivery IDs across retries;
- unsigned endpoint rejection;
- one-time replay claims;
- stale-event rejection.
Result:
5/5 targeted tests passed
Status:
TESTED — signed payment-webhook regression
This does not establish external receiver deployment, settlement, wallet security or broader infrastructure certification.
wasim-builds — fail-closed admin authentication
GitHub:
PR #860:
Canonical merge:
9c36d5be450e12345ff9251a40ab4df38839a7fe
The independent checkpoint reproduced:
unconfigured → 503
missing → 401
wrong → 401
correct → 200
Result:
4/4 targeted tests passed
Status:
TESTED — fail-closed admin-auth regression
Again, the claim is deliberately bounded to that regression behavior.
foxxx009 — KPI/evidence framework and automated testing
GitHub:
PR #894 — KPI/evidence framework:
50f70aab6dc9a909f65b81cb70d932706143afec
PR #259 — historical GitHubMonitor test contribution:
1c78fadd608e8c8acaeaeaf00d448676f82c3f91
The KPI/evidence framework was independently reproduced with synthetic data.
The historical #259 test suite was later re-enabled through maintainer integration PR #1526:
f8cbdee1e50cfbfa6925b4bc1014ca75ed5e90d1
That attribution distinction is intentional:
259 is contributor-authored work.
1526 is a maintainer-authored integration repair that made the historical test suite runnable again.
Good provenance should preserve that difference.
Why external repositories matter
A healthy open-source ecosystem should not require every contributor to surrender project independence.
We would rather support a model like:
CONTRIBUTOR PROJECT A ───┐
│
CONTRIBUTOR PROJECT B ───┼── reproducible bridges ── MYZUBSTER
│
CONTRIBUTOR PROJECT C ───┘
External projects can remain under their own ownership, architecture and release process.
MyZubster only needs a bounded interface or reproducible artifact when interoperability is useful.
Current examples include:
And the canonical ecosystem repository remains:
Evidence-first does not mean claim-first
One principle has become increasingly important during this work:
A passing test should prove exactly what it tested — and nothing more.
For example:
TESTED
≠ deployed
MERGED
≠ production-ready
security regression PASS
≠ security certification
research evidence
≠ professional credential
blockchain attestation
≠ proof that a physical event happened
contribution
≠ employment
verified contribution
≠ payment
Being precise about these boundaries makes public technical evidence more credible, not less.
Where we want to go next
The long-term direction is a contributor network where independent developers, researchers and maintainers can expose small interoperable capabilities without centralizing everything into one codebase.
A future graph could look like:
Contributor project
↓
public commit
↓
reproducible capability
↓
signed / bounded request
↓
another independent node
↓
public evidence result
The interesting milestone is not simply "more contributors".
It is:
more independently controlled projects that can prove small things to each other reproducibly.
That creates a much stronger foundation for open-source collaboration, decentralized infrastructure and evidence-driven automation.
Explore the project
Canonical repository:
github.com/MyZubster-Ecosystem/myzubster
External contributor projects:
- Nicola / N4K48 — myzubster-mvp
- Shweta-singh24 — MyZubsterGateway
- khongten124 — Open Period Care research project
If you maintain an independent open-source project and want to explore a small, reproducible interoperability checkpoint instead of a vague "integration", that is exactly the kind of experiment we are interested in.
One project. One bounded capability. One reproducible checkpoint. One public evidence trail.
Top comments (0)