aere-proof-of-software/tools/proof-of-software/action/action.yml
Aere Network 065f84e34a Aere Proof of Software 1.4.0: an attestation of what was built, from what, by whom and when, verifiable without trusting Aere Network
Every artifact's SHA-256 and size, the SBOM's digest, the git commit and tree of the source, a hybrid signature (classical + ML-DSA,
both required) and, when notarized, a first-seen time on Aere Network covered by the validators' post-quantum certificate. verify
recomputes everything from the files; --rebuild-from repeats an npm pack build from a clone the verifier chose; the SBOM is
re-derived from the committed package-lock.json or, new in 1.4.0, from the committed go.mod and go.sum; --signer requires the
signing keys you expect (1.4.0); a developer credential binds the keys to a person, judged against a trust root you choose. The
builder's declared date can only accuse, never acquit (1.4.0). Includes the GitHub Action and the hybrid signature library it uses.

Laid out as in the development repository (tools/proof-of-software/, sdk-pq-sign/, sdk/) so that nothing is rewritten for
publication. Tests and negative controls measured on 2026-09-29 are listed in README.md.
2026-09-29 22:46:57 +03:00

59 lines
2.7 KiB
YAML

name: Aere Proof of Software
description: >-
Attest an npm package built from the committed git tree, verify the attestation by rebuilding it from a clean clone
of the commit, optionally sign it (hybrid classical + ML-DSA) and notarize it on Aere Network (chain 2800).
author: Aere Network
branding:
icon: shield
color: blue
inputs:
source-path:
description: >-
Directory of the npm package inside the repository (for example packages/mylib). It must be a subdirectory of
the repository, with no uncommitted or untracked files: the artifact is npm pack of the COMMITTED tree.
required: true
build:
description: Build to record and repeat. This version supports only npm-pack (npm pack of the committed tree).
required: false
default: npm-pack
signing-key:
description: >-
Optional secret. The key file written by `pos.mjs keygen` (JSON, or base64 of it). When given, the statement is
signed with a hybrid signature (classical + ML-DSA, both required to verify).
required: false
aere-api-key:
description: >-
Optional secret. An Aere Cloud API key. When given, and only after the rebuild verification passed, the
statement hash is notarized on chain 2800 (POST https://cloud.aere.network/v1/notarize). Without it the
attestation is not notarized, and the step summary says so.
required: false
verify-rebuild:
description: >-
After attesting, clone the commit into a clean directory, repeat the build there and require the attested
digest byte for byte. The step fails if the artifact is not reproduced.
required: false
default: 'true'
out-dir:
description: >-
Directory for the artifact and the attestation file. Defaults to $RUNNER_TEMP/aere-proof-of-software, outside
the repository, so the run does not dirty the checkout. It may not be inside source-path.
required: false
outputs:
attestation-path:
description: Path of the attestation JSON file (upload it next to the release).
artifact-path:
description: Path of the attested .tgz. Publish this very file (npm publish <file>), not a new pack.
artifact-sha256:
description: SHA-256 of the artifact, 0x-prefixed hex.
tree:
description: Git tree hash of source-path at the attested commit.
statement-hash:
description: SHA-256 of the statement text; this is the digest that is signed and notarized.
notarized-tx:
description: Transaction hash of the notarization on chain 2800. Set only when the statement hash was notarized.
proof-url:
description: URL of the proof (GET /v1/proof/{statementHash}). Set only when the statement hash was notarized.
runs:
using: node24
main: index.mjs