Every artifact's SHA-256 and size, the SBOM's digest, the git commit and tree of the source, a hybrid signature (classical + ML-DSA, both required) and, when notarized, a first-seen time on Aere Network covered by the validators' post-quantum certificate. verify recomputes everything from the files; --rebuild-from repeats an npm pack build from a clone the verifier chose; the SBOM is re-derived from the committed package-lock.json or, new in 1.4.0, from the committed go.mod and go.sum; --signer requires the signing keys you expect (1.4.0); a developer credential binds the keys to a person, judged against a trust root you choose. The builder's declared date can only accuse, never acquit (1.4.0). Includes the GitHub Action and the hybrid signature library it uses. Laid out as in the development repository (tools/proof-of-software/, sdk-pq-sign/, sdk/) so that nothing is rewritten for publication. Tests and negative controls measured on 2026-09-29 are listed in README.md.
55 lines
2.2 KiB
YAML
55 lines
2.2 KiB
YAML
# Attest an npm package on every release tag: npm pack of the COMMITTED tree, attestation, rebuild check from a clean
|
|
# clone of the commit, optional hybrid signature, optional notarization on Aere Network (chain 2800).
|
|
#
|
|
# Repository secrets used (both optional):
|
|
# AERE_POS_SIGNING_KEY the key file written by `node tools/proof-of-software/pos.mjs keygen --out keys.json`
|
|
# (paste the JSON, or base64 of it). Keep keys.json itself off the repository.
|
|
# AERE_API_KEY an Aere Cloud API key; without it the attestation is not notarized, and the summary says so.
|
|
name: Attest npm package
|
|
|
|
on:
|
|
push:
|
|
tags: ['v*']
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
attest:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
# the default fetch-depth (1) is enough: the rebuild needs only the attested commit
|
|
- uses: actions/checkout@v4
|
|
|
|
# npm on PATH performs the pack; its version is recorded in the statement
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 22
|
|
|
|
- id: pos
|
|
# Reference this action by its directory in the repository that contains it, pinned to a full commit SHA.
|
|
uses: <owner>/<repo>/tools/proof-of-software/action@<full-commit-sha>
|
|
with:
|
|
source-path: packages/mylib
|
|
signing-key: ${{ secrets.AERE_POS_SIGNING_KEY }}
|
|
aere-api-key: ${{ secrets.AERE_API_KEY }}
|
|
# verify-rebuild: true (default; the step fails if the artifact is not reproduced byte for byte)
|
|
|
|
- uses: actions/upload-artifact@v4
|
|
with:
|
|
name: proof-of-software
|
|
path: |
|
|
${{ steps.pos.outputs.attestation-path }}
|
|
${{ steps.pos.outputs.artifact-path }}
|
|
|
|
# Optional: publish the very file that was attested, never a new pack.
|
|
# - run: npm publish "${{ steps.pos.outputs.artifact-path }}"
|
|
# env:
|
|
# NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
|
|
- run: |
|
|
echo "artifact sha256: ${{ steps.pos.outputs.artifact-sha256 }}"
|
|
echo "git tree: ${{ steps.pos.outputs.tree }}"
|
|
echo "statement hash: ${{ steps.pos.outputs.statement-hash }}"
|
|
echo "notarized tx: ${{ steps.pos.outputs.notarized-tx }}"
|