48 lines
3.1 KiB
Markdown
48 lines
3.1 KiB
Markdown
# Aere Proof of Software
|
|
|
|
An attestation of what was built, from what, by whom and when, that anyone can verify without trusting Aere Network. The tool and its
|
|
documentation are in [`tools/proof-of-software/`](tools/proof-of-software/README.md); start there.
|
|
|
|
The folders are laid out as in the development repository, because the tool, its tests and its GitHub Action find their two
|
|
dependencies by relative path, and nothing was rewritten for publication:
|
|
|
|
| folder | what it is |
|
|
|---|---|
|
|
| [`tools/proof-of-software/`](tools/proof-of-software/) | `pos.mjs` (attest, verify, rebuild, SBOM, ML-BOM, developer credentials), its tests and negative controls, and the GitHub Action in `action/` |
|
|
| [`sdk-pq-sign/`](sdk-pq-sign/) | the hybrid signature it uses: a classical scheme (secp256k1 or Ed25519) and ML-DSA (FIPS 204) over the same digest, both required; built on `@noble` |
|
|
| [`sdk/`](sdk/) | the Aere Cloud client, only for notarization and reading the on-chain proof; the same file as in `aere-cloud-sdk` |
|
|
|
|
## Install and check
|
|
|
|
```
|
|
cd sdk-pq-sign && npm ci --ignore-scripts && cd .. # the pinned @noble dependencies, integrity-checked
|
|
cd tools/proof-of-software
|
|
node pos.mjs keygen --out keys.json
|
|
node test/pos.test.mjs # and the other tests below
|
|
```
|
|
|
|
Node.js 22 or later, and git. Results measured on 2026-09-30 (Node.js 24.14.1, Windows; git 2.x, npm 11):
|
|
|
|
| test | result | negative control |
|
|
|---|---|---|
|
|
| attestation and verification | 16/16 (`test/pos.test.mjs`) | inside the test |
|
|
| ML-BOM of a model directory | 8/8 (`test/model.test.mjs`) | `test/model-control-negativ.mjs` edits `pos.mjs` in place and restores it; not run for this table |
|
|
| developer credential | 12/12 (`test/credential.test.mjs`) | 7/7 (`test/credential-control-negativ.mjs`) |
|
|
| who signed (`--signer`) | 7/7 (`test/semnatar.test.mjs`) | 4/4 (`test/semnatar-control-negativ.mjs`) |
|
|
| npm SBOM from the committed lockfile | 11/11 (`test/sbom.test.mjs`) | 5/5 (`test/sbom-control-negativ.mjs`) |
|
|
| Go SBOM from the committed go.sum | 14/14 (`test/sbom-go.test.mjs`) | 8/8 (`test/sbom-go-control-negativ.mjs`) |
|
|
| .NET and Gradle SBOMs from the committed lock files | 27/27 (`test/sbom-nuget-gradle.test.mjs`) | 20/20 (`test/sbom-nuget-gradle-control-negativ.mjs`) |
|
|
| hybrid signature library | 34/34 (`sdk-pq-sign/test/pq-sign.test.mjs`); its check of the ML-DSA half on chain is skipped without a Cloud key | inside the test |
|
|
| GitHub Action | `test/action.test.mjs` (long; installs pinned dependencies from the npm registry) | not measured for this publication |
|
|
|
|
The GitHub Action is in this repository, which lives on git.aere.network; GitHub runs actions only from GitHub repositories, so
|
|
to use it, copy these three folders into a GitHub repository you control and point `uses:` at it, pinned to a full commit SHA
|
|
(`tools/proof-of-software/action/README.md`).
|
|
|
|
Code comments, test names and control messages are in Romanian; the command line, its output, the data formats, error messages and
|
|
the documentation are in English. No third party has reviewed this code.
|
|
|
|
## Licence
|
|
|
|
MIT, see [LICENSE](LICENSE). Files: 48 (tools/proof-of-software 37, sdk-pq-sign 6, sdk 3).
|