Every artifact's SHA-256 and size, the SBOM's digest, the git commit and tree of the source, a hybrid signature (classical + ML-DSA, both required) and, when notarized, a first-seen time on Aere Network covered by the validators' post-quantum certificate. verify recomputes everything from the files; --rebuild-from repeats an npm pack build from a clone the verifier chose; the SBOM is re-derived from the committed package-lock.json or, new in 1.4.0, from the committed go.mod and go.sum; --signer requires the signing keys you expect (1.4.0); a developer credential binds the keys to a person, judged against a trust root you choose. The builder's declared date can only accuse, never acquit (1.4.0). Includes the GitHub Action and the hybrid signature library it uses. Laid out as in the development repository (tools/proof-of-software/, sdk-pq-sign/, sdk/) so that nothing is rewritten for publication. Tests and negative controls measured on 2026-09-29 are listed in README.md.
59 lines
2.7 KiB
YAML
59 lines
2.7 KiB
YAML
name: Aere Proof of Software
|
|
description: >-
|
|
Attest an npm package built from the committed git tree, verify the attestation by rebuilding it from a clean clone
|
|
of the commit, optionally sign it (hybrid classical + ML-DSA) and notarize it on Aere Network (chain 2800).
|
|
author: Aere Network
|
|
branding:
|
|
icon: shield
|
|
color: blue
|
|
inputs:
|
|
source-path:
|
|
description: >-
|
|
Directory of the npm package inside the repository (for example packages/mylib). It must be a subdirectory of
|
|
the repository, with no uncommitted or untracked files: the artifact is npm pack of the COMMITTED tree.
|
|
required: true
|
|
build:
|
|
description: Build to record and repeat. This version supports only npm-pack (npm pack of the committed tree).
|
|
required: false
|
|
default: npm-pack
|
|
signing-key:
|
|
description: >-
|
|
Optional secret. The key file written by `pos.mjs keygen` (JSON, or base64 of it). When given, the statement is
|
|
signed with a hybrid signature (classical + ML-DSA, both required to verify).
|
|
required: false
|
|
aere-api-key:
|
|
description: >-
|
|
Optional secret. An Aere Cloud API key. When given, and only after the rebuild verification passed, the
|
|
statement hash is notarized on chain 2800 (POST https://cloud.aere.network/v1/notarize). Without it the
|
|
attestation is not notarized, and the step summary says so.
|
|
required: false
|
|
verify-rebuild:
|
|
description: >-
|
|
After attesting, clone the commit into a clean directory, repeat the build there and require the attested
|
|
digest byte for byte. The step fails if the artifact is not reproduced.
|
|
required: false
|
|
default: 'true'
|
|
out-dir:
|
|
description: >-
|
|
Directory for the artifact and the attestation file. Defaults to $RUNNER_TEMP/aere-proof-of-software, outside
|
|
the repository, so the run does not dirty the checkout. It may not be inside source-path.
|
|
required: false
|
|
outputs:
|
|
attestation-path:
|
|
description: Path of the attestation JSON file (upload it next to the release).
|
|
artifact-path:
|
|
description: Path of the attested .tgz. Publish this very file (npm publish <file>), not a new pack.
|
|
artifact-sha256:
|
|
description: SHA-256 of the artifact, 0x-prefixed hex.
|
|
tree:
|
|
description: Git tree hash of source-path at the attested commit.
|
|
statement-hash:
|
|
description: SHA-256 of the statement text; this is the digest that is signed and notarized.
|
|
notarized-tx:
|
|
description: Transaction hash of the notarization on chain 2800. Set only when the statement hash was notarized.
|
|
proof-url:
|
|
description: URL of the proof (GET /v1/proof/{statementHash}). Set only when the statement hash was notarized.
|
|
runs:
|
|
using: node24
|
|
main: index.mjs
|