aere-proof-of-software/tools/proof-of-software/action/examples/attest-npm-package.yml
Aere Network 065f84e34a Aere Proof of Software 1.4.0: an attestation of what was built, from what, by whom and when, verifiable without trusting Aere Network
Every artifact's SHA-256 and size, the SBOM's digest, the git commit and tree of the source, a hybrid signature (classical + ML-DSA,
both required) and, when notarized, a first-seen time on Aere Network covered by the validators' post-quantum certificate. verify
recomputes everything from the files; --rebuild-from repeats an npm pack build from a clone the verifier chose; the SBOM is
re-derived from the committed package-lock.json or, new in 1.4.0, from the committed go.mod and go.sum; --signer requires the
signing keys you expect (1.4.0); a developer credential binds the keys to a person, judged against a trust root you choose. The
builder's declared date can only accuse, never acquit (1.4.0). Includes the GitHub Action and the hybrid signature library it uses.

Laid out as in the development repository (tools/proof-of-software/, sdk-pq-sign/, sdk/) so that nothing is rewritten for
publication. Tests and negative controls measured on 2026-09-29 are listed in README.md.
2026-09-29 22:46:57 +03:00

55 lines
2.2 KiB
YAML

# Attest an npm package on every release tag: npm pack of the COMMITTED tree, attestation, rebuild check from a clean
# clone of the commit, optional hybrid signature, optional notarization on Aere Network (chain 2800).
#
# Repository secrets used (both optional):
# AERE_POS_SIGNING_KEY the key file written by `node tools/proof-of-software/pos.mjs keygen --out keys.json`
# (paste the JSON, or base64 of it). Keep keys.json itself off the repository.
# AERE_API_KEY an Aere Cloud API key; without it the attestation is not notarized, and the summary says so.
name: Attest npm package
on:
push:
tags: ['v*']
permissions:
contents: read
jobs:
attest:
runs-on: ubuntu-latest
steps:
# the default fetch-depth (1) is enough: the rebuild needs only the attested commit
- uses: actions/checkout@v4
# npm on PATH performs the pack; its version is recorded in the statement
- uses: actions/setup-node@v4
with:
node-version: 22
- id: pos
# Reference this action by its directory in the repository that contains it, pinned to a full commit SHA.
uses: <owner>/<repo>/tools/proof-of-software/action@<full-commit-sha>
with:
source-path: packages/mylib
signing-key: ${{ secrets.AERE_POS_SIGNING_KEY }}
aere-api-key: ${{ secrets.AERE_API_KEY }}
# verify-rebuild: true (default; the step fails if the artifact is not reproduced byte for byte)
- uses: actions/upload-artifact@v4
with:
name: proof-of-software
path: |
${{ steps.pos.outputs.attestation-path }}
${{ steps.pos.outputs.artifact-path }}
# Optional: publish the very file that was attested, never a new pack.
# - run: npm publish "${{ steps.pos.outputs.artifact-path }}"
# env:
# NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
- run: |
echo "artifact sha256: ${{ steps.pos.outputs.artifact-sha256 }}"
echo "git tree: ${{ steps.pos.outputs.tree }}"
echo "statement hash: ${{ steps.pos.outputs.statement-hash }}"
echo "notarized tx: ${{ steps.pos.outputs.notarized-tx }}"