name: Aere Proof of Software description: >- Attest an npm package built from the committed git tree, verify the attestation by rebuilding it from a clean clone of the commit, optionally sign it (hybrid classical + ML-DSA) and notarize it on Aere Network (chain 2800). author: Aere Network branding: icon: shield color: blue inputs: source-path: description: >- Directory of the npm package inside the repository (for example packages/mylib). It must be a subdirectory of the repository, with no uncommitted or untracked files: the artifact is npm pack of the COMMITTED tree. required: true build: description: Build to record and repeat. This version supports only npm-pack (npm pack of the committed tree). required: false default: npm-pack signing-key: description: >- Optional secret. The key file written by `pos.mjs keygen` (JSON, or base64 of it). When given, the statement is signed with a hybrid signature (classical + ML-DSA, both required to verify). required: false aere-api-key: description: >- Optional secret. An Aere Cloud API key. When given, and only after the rebuild verification passed, the statement hash is notarized on chain 2800 (POST https://cloud.aere.network/v1/notarize). Without it the attestation is not notarized, and the step summary says so. required: false verify-rebuild: description: >- After attesting, clone the commit into a clean directory, repeat the build there and require the attested digest byte for byte. The step fails if the artifact is not reproduced. required: false default: 'true' out-dir: description: >- Directory for the artifact and the attestation file. Defaults to $RUNNER_TEMP/aere-proof-of-software, outside the repository, so the run does not dirty the checkout. It may not be inside source-path. required: false outputs: attestation-path: description: Path of the attestation JSON file (upload it next to the release). artifact-path: description: Path of the attested .tgz. Publish this very file (npm publish ), not a new pack. artifact-sha256: description: SHA-256 of the artifact, 0x-prefixed hex. tree: description: Git tree hash of source-path at the attested commit. statement-hash: description: SHA-256 of the statement text; this is the digest that is signed and notarized. notarized-tx: description: Transaction hash of the notarization on chain 2800. Set only when the statement hash was notarized. proof-url: description: URL of the proof (GET /v1/proof/{statementHash}). Set only when the statement hash was notarized. runs: using: node24 main: index.mjs