Aere Proof of Software: what was built, from what, by whom and when, verifiable without trusting Aere Network (hybrid ML-DSA signatures, rebuild from the committed tree, SBOM re-derived from the committed lockfile, developer credentials)
Go to file
Aere Network 065f84e34a Aere Proof of Software 1.4.0: an attestation of what was built, from what, by whom and when, verifiable without trusting Aere Network
Every artifact's SHA-256 and size, the SBOM's digest, the git commit and tree of the source, a hybrid signature (classical + ML-DSA,
both required) and, when notarized, a first-seen time on Aere Network covered by the validators' post-quantum certificate. verify
recomputes everything from the files; --rebuild-from repeats an npm pack build from a clone the verifier chose; the SBOM is
re-derived from the committed package-lock.json or, new in 1.4.0, from the committed go.mod and go.sum; --signer requires the
signing keys you expect (1.4.0); a developer credential binds the keys to a person, judged against a trust root you choose. The
builder's declared date can only accuse, never acquit (1.4.0). Includes the GitHub Action and the hybrid signature library it uses.

Laid out as in the development repository (tools/proof-of-software/, sdk-pq-sign/, sdk/) so that nothing is rewritten for
publication. Tests and negative controls measured on 2026-09-29 are listed in README.md.
2026-09-29 22:46:57 +03:00
sdk Aere Proof of Software 1.4.0: an attestation of what was built, from what, by whom and when, verifiable without trusting Aere Network 2026-09-29 22:46:57 +03:00
sdk-pq-sign Aere Proof of Software 1.4.0: an attestation of what was built, from what, by whom and when, verifiable without trusting Aere Network 2026-09-29 22:46:57 +03:00
tools/proof-of-software Aere Proof of Software 1.4.0: an attestation of what was built, from what, by whom and when, verifiable without trusting Aere Network 2026-09-29 22:46:57 +03:00
LICENSE Aere Proof of Software 1.4.0: an attestation of what was built, from what, by whom and when, verifiable without trusting Aere Network 2026-09-29 22:46:57 +03:00
README.md Aere Proof of Software 1.4.0: an attestation of what was built, from what, by whom and when, verifiable without trusting Aere Network 2026-09-29 22:46:57 +03:00

Aere Proof of Software

An attestation of what was built, from what, by whom and when, that anyone can verify without trusting Aere Network. The tool and its documentation are in tools/proof-of-software/; start there.

The folders are laid out as in the development repository, because the tool, its tests and its GitHub Action find their two dependencies by relative path, and nothing was rewritten for publication:

folder what it is
tools/proof-of-software/ pos.mjs (attest, verify, rebuild, SBOM, ML-BOM, developer credentials), its tests and negative controls, and the GitHub Action in action/
sdk-pq-sign/ the hybrid signature it uses: a classical scheme (secp256k1 or Ed25519) and ML-DSA (FIPS 204) over the same digest, both required; built on @noble
sdk/ the Aere Cloud client, only for notarization and reading the on-chain proof; the same file as in aere-cloud-sdk

Install and check

cd sdk-pq-sign && npm ci --ignore-scripts && cd ..        # the pinned @noble dependencies, integrity-checked
cd tools/proof-of-software
node pos.mjs keygen --out keys.json
node test/pos.test.mjs                                    # and the other tests below

Node.js 22 or later, and git. Results measured on 2026-09-29 (Node.js 24.14.1, Windows; git 2.x, npm 11):

test result negative control
attestation and verification 16/16 (test/pos.test.mjs) inside the test
ML-BOM of a model directory 8/8 (test/model.test.mjs) test/model-control-negativ.mjs edits pos.mjs in place and restores it; not run for this table
developer credential 12/12 (test/credential.test.mjs) 7/7 (test/credential-control-negativ.mjs)
who signed (--signer) 7/7 (test/semnatar.test.mjs) 4/4 (test/semnatar-control-negativ.mjs)
npm SBOM from the committed lockfile 8/8 (test/sbom.test.mjs) 3/3 (test/sbom-control-negativ.mjs)
Go SBOM from the committed go.sum 13/13 (test/sbom-go.test.mjs) 7/7 (test/sbom-go-control-negativ.mjs)
hybrid signature library 34/34 (sdk-pq-sign/test/pq-sign.test.mjs); its check of the ML-DSA half on chain is skipped without a Cloud key inside the test
GitHub Action test/action.test.mjs (long; installs pinned dependencies from the npm registry) not measured for this publication

The GitHub Action is in this repository, which lives on git.aere.network; GitHub runs actions only from GitHub repositories, so to use it, copy these three folders into a GitHub repository you control and point uses: at it, pinned to a full commit SHA (tools/proof-of-software/action/README.md).

Code comments, test names and control messages are in Romanian; the command line, its output, the data formats, error messages and the documentation are in English. No third party has reviewed this code.

Licence

MIT, see LICENSE. Files: 35 (tools/proof-of-software 24, sdk-pq-sign 6, sdk 3).