593 B
593 B
SBOM→VEX Offline Kit (Stub)
This kit supports sprint task 6 (SBOM-VEX-GAPS-300-013).
Contents (stub):
verify.sh– chain hash stub for SBOM + DSSE + Rekor + VEXchain-hash-recipe.md– canonicalisation stepsinputs.lock– pinned tool versions and snapshotproof-manifest.json– chain hash placeholder– archived (empty placeholder)sbom-vex-blueprint.svg
Next steps:
- Add real SBOM/VEX samples and Rekor bundle snapshot.
- Produce DSSE signatures for proof manifest and scripts.
- Include time-anchor and backpressure/error policy notes per BP1–BP10.