- Created draft documentation for enabling reachability, CLI authentication, EntryTrace heuristics, Go stripped binaries, Java and Python lockfiles, Rust fingerprint enrichment, SAST integration, Windows/macOS analyzer coverage, scanner engine surface, multi-tenancy operations, RLS and data isolation, ABAC overlays, VEX trust model, VEX ops runbook, VEX mapping, scopes and roles, tenancy overview, VEX signatures, contract testing, VEX consensus algorithm, VEX consensus API, VEX consensus console, VEX consensus overview, and VEX issuer directory. - Each document includes a status placeholder, purpose, and open TODOs for future updates.
410 B
410 B
VEX Signatures — Draft Skeleton (2025-12-05 UTC)
Status: draft placeholder. Inputs pending: security review (DVDO0110), key rotation plan.
Verification Flow
- How signatures are verified; trust roots (to fill).
Rotation
- Key rotation process; expiry handling.
Audit
- Logging, evidence capture, review cadence.
Open TODOs
- Insert concrete commands/config once security review completes.