aere-proof-of-software/README.md

3.1 KiB

Aere Proof of Software

An attestation of what was built, from what, by whom and when, that anyone can verify without trusting Aere Network. The tool and its documentation are in tools/proof-of-software/; start there.

The folders are laid out as in the development repository, because the tool, its tests and its GitHub Action find their two dependencies by relative path, and nothing was rewritten for publication:

folder what it is
tools/proof-of-software/ pos.mjs (attest, verify, rebuild, SBOM, ML-BOM, developer credentials), its tests and negative controls, and the GitHub Action in action/
sdk-pq-sign/ the hybrid signature it uses: a classical scheme (secp256k1 or Ed25519) and ML-DSA (FIPS 204) over the same digest, both required; built on @noble
sdk/ the Aere Cloud client, only for notarization and reading the on-chain proof; the same file as in aere-cloud-sdk

Install and check

cd sdk-pq-sign && npm ci --ignore-scripts && cd ..        # the pinned @noble dependencies, integrity-checked
cd tools/proof-of-software
node pos.mjs keygen --out keys.json
node test/pos.test.mjs                                    # and the other tests below

Node.js 22 or later, and git. Results measured on 2026-09-30 (Node.js 24.14.1, Windows; git 2.x, npm 11):

test result negative control
attestation and verification 16/16 (test/pos.test.mjs) inside the test
ML-BOM of a model directory 8/8 (test/model.test.mjs) test/model-control-negativ.mjs edits pos.mjs in place and restores it; not run for this table
developer credential 12/12 (test/credential.test.mjs) 7/7 (test/credential-control-negativ.mjs)
who signed (--signer) 7/7 (test/semnatar.test.mjs) 4/4 (test/semnatar-control-negativ.mjs)
npm SBOM from the committed lockfile 11/11 (test/sbom.test.mjs) 5/5 (test/sbom-control-negativ.mjs)
Go SBOM from the committed go.sum 14/14 (test/sbom-go.test.mjs) 8/8 (test/sbom-go-control-negativ.mjs)
.NET and Gradle SBOMs from the committed lock files 27/27 (test/sbom-nuget-gradle.test.mjs) 20/20 (test/sbom-nuget-gradle-control-negativ.mjs)
hybrid signature library 34/34 (sdk-pq-sign/test/pq-sign.test.mjs); its check of the ML-DSA half on chain is skipped without a Cloud key inside the test
GitHub Action test/action.test.mjs (long; installs pinned dependencies from the npm registry) not measured for this publication

The GitHub Action is in this repository, which lives on git.aere.network; GitHub runs actions only from GitHub repositories, so to use it, copy these three folders into a GitHub repository you control and point uses: at it, pinned to a full commit SHA (tools/proof-of-software/action/README.md).

Code comments, test names and control messages are in Romanian; the command line, its output, the data formats, error messages and the documentation are in English. No third party has reviewed this code.

Licence

MIT, see LICENSE. Files: 48 (tools/proof-of-software 37, sdk-pq-sign 6, sdk 3).