sbom_tool: "syft 1.1.0" vex_tool: "stella-vex 0.4.2" dsse_tool: "cosign 2.2.1" rekor_snapshot: "rekor-snapshot-2025-11-30.json" chain_hash_alg: "sha256" tz: "UTC" notes: "Offline kit; no live Rekor calls"