{ "@type": "https://stellaops.dev/predicates/proof-of-exposure@v1", "evidence": { "graphHash": "blake3:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0", "sbomRef": "cas://scanner-artifacts/sbom.cdx.json" }, "metadata": { "analyzer": { "name": "stellaops-scanner", "toolchainDigest": "sha256:678901234567890123456789012345678901234567890123456789012345", "version": "1.2.0" }, "generatedAt": "2025-12-23T13:00:00.000Z", "policy": { "evaluatedAt": "2025-12-23T12:58:00.000Z", "policyDigest": "sha256:901234567890123456789012345678901234567890123456789012345678", "policyId": "prod-release-v42" }, "reproSteps": [ "1. Build container image from Dockerfile (commit: jkl012)", "2. Run scanner with config: etc/scanner.yaml", "3. Extract reachability graph with maxDepth=10 (stripped binary)", "4. Resolve CVE-2024-99999 to vulnerable code addresses via binary diffing" ] }, "schema": "stellaops.dev/poe@v1", "subject": { "buildId": "gnu-build-id:c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9", "componentRef": "pkg:generic/libcrypto.so.1.1@1.1.1k", "imageDigest": "sha256:jkl012345678901234567890123456789012345678901234567890123456", "vulnId": "CVE-2024-99999" }, "subgraph": { "edges": [ { "confidence": 0.94, "from": "code_id:0x401530", "to": "code_id:0x402140" }, { "confidence": 0.91, "from": "code_id:0x402140", "to": "code_id:0x403880" }, { "confidence": 0.89, "from": "code_id:0x403880", "to": "code_id:0x405220" }, { "confidence": 0.87, "from": "code_id:0x405220", "to": "code_id:0x407b40" }, { "confidence": 0.85, "from": "code_id:0x407b40", "to": "code_id:0x409c60" } ], "entryRefs": [ "code_id:0x401530" ], "nodes": [ { "addr": "0x401530", "id": "code_id:0x401530", "moduleHash": "sha256:701234567890123456789012345678901234567890123456789012345678", "symbol": "" }, { "addr": "0x402140", "id": "code_id:0x402140", "moduleHash": "sha256:701234567890123456789012345678901234567890123456789012345678", "symbol": "" }, { "addr": "0x403880", "id": "code_id:0x403880", "moduleHash": "sha256:701234567890123456789012345678901234567890123456789012345678", "symbol": "" }, { "addr": "0x405220", "id": "code_id:0x405220", "moduleHash": "sha256:712345678901234567890123456789012345678901234567890123456789", "symbol": "" }, { "addr": "0x407b40", "id": "code_id:0x407b40", "moduleHash": "sha256:712345678901234567890123456789012345678901234567890123456789", "symbol": "" }, { "addr": "0x409c60", "id": "code_id:0x409c60", "moduleHash": "sha256:723456789012345678901234567890123456789012345678901234567890", "symbol": "" } ], "sinkRefs": [ "code_id:0x409c60" ] } }