# Aere Proof of Software An attestation of what was built, from what, by whom and when, that anyone can verify without trusting Aere Network. The tool and its documentation are in [`tools/proof-of-software/`](tools/proof-of-software/README.md); start there. The folders are laid out as in the development repository, because the tool, its tests and its GitHub Action find their two dependencies by relative path, and nothing was rewritten for publication: | folder | what it is | |---|---| | [`tools/proof-of-software/`](tools/proof-of-software/) | `pos.mjs` (attest, verify, rebuild, SBOM, ML-BOM, developer credentials), its tests and negative controls, and the GitHub Action in `action/` | | [`sdk-pq-sign/`](sdk-pq-sign/) | the hybrid signature it uses: a classical scheme (secp256k1 or Ed25519) and ML-DSA (FIPS 204) over the same digest, both required; built on `@noble` | | [`sdk/`](sdk/) | the Aere Cloud client, only for notarization and reading the on-chain proof; the same file as in `aere-cloud-sdk` | ## Install and check ``` cd sdk-pq-sign && npm ci --ignore-scripts && cd .. # the pinned @noble dependencies, integrity-checked cd tools/proof-of-software node pos.mjs keygen --out keys.json node test/pos.test.mjs # and the other tests below ``` Node.js 22 or later, and git. Results measured on 2026-09-30 (Node.js 24.14.1, Windows; git 2.x, npm 11): | test | result | negative control | |---|---|---| | attestation and verification | 16/16 (`test/pos.test.mjs`) | inside the test | | ML-BOM of a model directory | 8/8 (`test/model.test.mjs`) | `test/model-control-negativ.mjs` edits `pos.mjs` in place and restores it; not run for this table | | developer credential | 12/12 (`test/credential.test.mjs`) | 7/7 (`test/credential-control-negativ.mjs`) | | who signed (`--signer`) | 7/7 (`test/semnatar.test.mjs`) | 4/4 (`test/semnatar-control-negativ.mjs`) | | npm SBOM from the committed lockfile | 11/11 (`test/sbom.test.mjs`) | 5/5 (`test/sbom-control-negativ.mjs`) | | Go SBOM from the committed go.sum | 14/14 (`test/sbom-go.test.mjs`) | 8/8 (`test/sbom-go-control-negativ.mjs`) | | .NET and Gradle SBOMs from the committed lock files | 27/27 (`test/sbom-nuget-gradle.test.mjs`) | 20/20 (`test/sbom-nuget-gradle-control-negativ.mjs`) | | hybrid signature library | 34/34 (`sdk-pq-sign/test/pq-sign.test.mjs`); its check of the ML-DSA half on chain is skipped without a Cloud key | inside the test | | GitHub Action | `test/action.test.mjs` (long; installs pinned dependencies from the npm registry) | not measured for this publication | The GitHub Action is in this repository, which lives on git.aere.network; GitHub runs actions only from GitHub repositories, so to use it, copy these three folders into a GitHub repository you control and point `uses:` at it, pinned to a full commit SHA (`tools/proof-of-software/action/README.md`). Code comments, test names and control messages are in Romanian; the command line, its output, the data formats, error messages and the documentation are in English. No third party has reviewed this code. ## Licence MIT, see [LICENSE](LICENSE). Files: 48 (tools/proof-of-software 37, sdk-pq-sign 6, sdk 3).