Qwen /Qwen2.5-0.5B-Instruct
Verdict
AdmittedNo findings: every admission gate passed for this revision.
A verdict covers licence, provenance and files. Quality and fit on your own tasks are measured by Compare.
What was checked
-
Licence Concluded
Apache-2.0, from a licence file (T1).
-
Provenance Verified
The licensor's own repository.
-
Files Verified
Safetensors, with the weights digest verified at admission.
-
Export screening Not yet assessed
No export claim is made.
Verify this verdict
Download attestation.json and check it against the published key:
python scripts/verify-verdict.py
Full record
- Revision
7ae557604adf67be 50417f59 c2c2f167 def9a775 - Date assessed
- 2026-09-15 BACKFILL
- Upstream released
- 2024-09-25T12:32:56Z, the commit date of the assessed revision, recorded 2026-09-25. A reconstruction: this verdict was assessed before upstream release tracking began, so it is excluded from the median.
- Release to verdict
- Verdict latency: 17267 hours from the upstream release to 00:00 UTC on the assessment date. The record is dated, not timed, so the true figure may be up to 24 hours higher.
- Provenance label
- the weights digest was verified against the file at admission, and the source is the licensor's own repository
- Licence, declared and concluded
- Declared: Apache-2.0 (as a licence-file). Concluded: Apache-2.0.
- Evidence tier
- T1 a licence file in the model repository. Sufficient for Class A.
- Deviation from canonical text
- None against the pinned canonical text. On this evidence path the declared text is the pinned canonical file itself, so no byte comparison of the licensor's own licence file is claimed.
- Added-clause screen
- Run over the declared sibling policy files; none were declared for this model.
- Provenance chain
- Source: huggingface.co/Qwen/Qwen2.5-0.5B-Instruct. Official licensor repository: yes.
- Base lineage
- Not a derivative recorded in the admission record, so no base licence obligations arise.
- Base-licence obligations
- None recorded: this is not a derivative, or the base's conditions were not engaged.
- Contradiction triage
- None recorded.
- Files and integrity
- safetensors; the weights digest was verified against the file at admission.
- Export screen
- Export screening: not yet assessed. No export claim is made. The record carries status: not_assessed, basis: null, assessed_by: null, assessed_date: null, reference: null.
- Declared training data
- not recorded in the admission record.
- What was checked
- Canonical text pinned and digest-verified, identifier taken from the licensor's own repository metadata, added-clause screen run over sibling policy files, provenance chain recorded. The licensor's own licence file is not compared byte for byte on this evidence path.
- Signed attestation
- attestation.json: a DSSE envelope over an in-toto Statement v1, whose subject is the weights file digests and whose predicate is this record's provenance artefact. Signed with the key published at /verdicts/keys/, which states the fingerprint, the date the key came into use and how to verify the signature. Key custody: a local key on one operator host, not an HSM.
Running models like this in your own estate? Heliast runs the same gate inside your environment, on your policy.
Book a discovery session