// SBOM · NO_LOGIN_REQUIRED
// COVERAGE
| Repository | Ecosystem | SBOM |
|---|---|---|
| a3e9-audit-client | Rust / Cargo | Published — 0 components |
| a3e9-chain-router | Container / Debian + Rust | Published — 2 products, 1,673 components |
| a3e9-identity | Container / Debian + Rust | Published — 2 products, 890 components |
| a3e9-mpc-multiplexer | Container / Debian + Rust | Published — 2 products, 623 components |
| a3e9-notary | Container / Debian + Rust | Published — 2 products, 799 components |
| a3e9-rwa-evaluator | Container / Debian + Rust | Published — 2 products, 538 components |
| a3e9-tinl | Rust / Cargo | Published — 3 products, 1,425 components |
| a3e9-website | Container / Debian + Node.js | Published — 2 products, 3,662 components |
| HSM | C++ / Make | None. The signing service publishes a CBOM rather than an SBOM today: its cryptographic inventory is generated from a source scan with a CI drift gate, but no dependency-graph generator has been run against its CMake and system-package inputs. The CBOM is the artifact under /evidence/cbom; it inventories cryptography, not packages. |
| a3e9-attestation | C++ / Make | None. Builds a runtime attestation artifact — a Merkle root over the loaded shared libraries, signed by the HSM and checked at daemon startup. That is evidence about a running process, not a CycloneDX dependency graph, and converting it would break the startup check that consumes it. A separate CycloneDX SBOM has not been generated yet. |
| a3e9-contracts | Foundry / Solidity | None. Dependencies are pinned as git submodules rather than through a package lockfile, so the pin is a commit SHA and no off-the-shelf generator reads it. Assembling the SBOM from submodule state is straightforward and has not been done yet. |
| a3e9-evaluator | Python / CMake / Docker | None. No lock file exists — no requirements, pyproject, poetry or uv inputs to resolve. An SBOM generated from the source tree alone would describe intent rather than what a build installs, so the honest options are to resolve from the built image or to declare the gap. It is declared. |
| a3e9-ip | Documents | None. Ships no software. Business and legal documents only, with nothing to build, package or install. Recorded here so the absence is a decision on the page rather than a repository that quietly went missing from it. |
Limit
// DOWNLOAD
Audit client · Shared library · Rust / Cargo
CycloneDX 1.5 · 2 KB
Safe Rust wrapper over the HSM audit trail's C ABI, so services write into the same HMAC-chained trail rather than reimplementing the wire format.
0 components · 1 dependency edges
Generated by cargo-cyclonedx 0.5.9
sha256 6a285ca23c7dd55bac719f5d7f9e9e5d7e403d0d2952e8e142c5ad344fc27e20
Chain router — container image · Shipped image · Container / Debian + Rust
CycloneDX 1.7 · 2.1 MB
The shipped image for the chain router, including the Debian base packages the source-resolved SBOM does not cover. Built with its private dependency fetched from a local mirror at the pinned commit — see the reconciliation note.
1,093 components · 837 dependency edges
Generated by syft 1.51.0
Licences: BSD-3-Clause (30), GPL-2.0-only (19), BSD-2-Clause (10), Apache-2.0 (8), sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816 (4), BSD-4-Clause-UC (3), 987 with no declared licence
sha256 7b349b6eec0fa066b680580361801e6e574e68ca6cfeff913da0bddd9329d92b
Chain router · Service · Rust / Cargo
CycloneDX 1.5 · 754 KB
Routes signing requests across chains.
580 components · 581 dependency edges
Generated by cargo-cyclonedx 0.5.9
Licences: MIT OR Apache-2.0 (249), Apache-2.0 (121), MIT (77), Apache-2.0 OR MIT (53), Unicode-3.0 (18), CC0-1.0 (14)
sha256 907b47e60ac656d1fa0bdbda6cf696aeec3b002cd97b496151d84a0803408927
Identity service — container image · Shipped image · Container / Debian + Rust
CycloneDX 1.7 · 1.1 MB
The shipped image for the identity service, including the Debian base packages the source-resolved SBOM does not cover. Built with its private dependency fetched from a local mirror at the pinned commit — see the reconciliation note.
615 components · 443 dependency edges
Generated by syft 1.51.0
Licences: BSD-3-Clause (30), GPL-2.0-only (19), BSD-2-Clause (10), Apache-2.0 (8), sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816 (4), BSD-4-Clause-UC (3), 509 with no declared licence
sha256 cb6125aa85b0c7b20d4310eff0edaaefa4269d301fcd16c47d805fa76eaf99d5
Identity service · Service · Rust / Cargo
CycloneDX 1.5 · 339 KB
Identity and policy service.
275 components · 276 dependency edges
Generated by cargo-cyclonedx 0.5.9
Licences: MIT OR Apache-2.0 (155), MIT (42), Apache-2.0 OR MIT (28), Unicode-3.0 (18), MPL-2.0 (5), BSD-3-Clause (3)
sha256 b7e528d740dec82a4e805813eaf5dccd0b625bf4c91944154e53d4fc80f91c5b
MPC multiplexer — container image · Shipped image · Container / Debian + Rust
CycloneDX 1.7 · 880 KB
The shipped image for the MPC multiplexer, including the Debian base packages the source-resolved SBOM does not cover.
429 components · 303 dependency edges
Generated by syft 1.51.0
Licences: BSD-3-Clause (30), GPL-2.0-only (19), BSD-2-Clause (10), Apache-2.0 (8), sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816 (4), BSD-4-Clause-UC (3), 323 with no declared licence
sha256 6f9fa2cd589238e73faf02be138e64700c6974d6452a5f48d67b966aeb43e8ff
MPC multiplexer · Service · Rust / Cargo
CycloneDX 1.5 · 237 KB
Multiplexes MPC provisioning sessions.
194 components · 195 dependency edges
Generated by cargo-cyclonedx 0.5.9
Licences: MIT OR Apache-2.0 (95), MIT (38), Unicode-3.0 (18), Apache-2.0 OR MIT (14), Apache-2.0 (5), Apache-2.0 OR ISC OR MIT (4)
sha256 d530a9c3bb602730b429f25ae3c01a517e055aa7b7c1dda155ad4e6b5be92944
Notary — container image · Shipped image · Container / Debian + Rust
CycloneDX 1.7 · 1.0 MB
The whole shipped image, not just the Rust graph: the Debian base and its packages alongside the compiled binaries. Scanned from the built image by digest. This is the inventory that answers a CVE question about the OS layer, which the source-resolved SBOM covers none of.
543 components · 385 dependency edges
Generated by syft 1.51.0
Licences: BSD-3-Clause (30), GPL-2.0-only (19), BSD-2-Clause (10), Apache-2.0 (8), sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816 (4), BSD-4-Clause-UC (3), 437 with no declared licence
sha256 aa06f74db4a05625b2383ac3978d670e76441e279f6453e4b2edafeae1f5b423
Notary · Service · Rust / Cargo
CycloneDX 1.5 · 313 KB
Notarisation service.
256 components · 257 dependency edges
Generated by cargo-cyclonedx 0.5.9
Licences: MIT OR Apache-2.0 (126), MIT (41), Apache-2.0 OR MIT (40), Unicode-3.0 (18), Apache-2.0 (5), Apache-2.0 OR ISC OR MIT (3)
sha256 652edd4489c04f356ecd2859d923689d4566a6ccd4420b48ea1dfc0bf784a8ec
RWA evaluator — container image · Shipped image · Container / Debian + Rust
CycloneDX 1.7 · 694 KB
The shipped image for the RWA evaluator, including the Debian base packages the source-resolved SBOM does not cover.
315 components · 233 dependency edges
Generated by syft 1.51.0
Licences: BSD-3-Clause (30), GPL-2.0-only (19), BSD-2-Clause (10), Apache-2.0 (8), sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816 (4), BSD-4-Clause-UC (3), 209 with no declared licence
sha256 ddc4db2bcd1742706e29190a69e49909687a9e593031e7bcad6b26999890d4b7
RWA evaluator · Service · Rust / Cargo
CycloneDX 1.5 · 273 KB
Real-world-asset evaluation service.
223 components · 224 dependency edges
Generated by cargo-cyclonedx 0.5.9
Licences: MIT OR Apache-2.0 (124), MIT (38), Apache-2.0 OR MIT (21), Unicode-3.0 (18), ISC (3), Unlicense OR MIT (3)
sha256 1190df227e17d2a7309559fa4e697768b790a08a8dd39379e743e4820df1b654
TINL core · Shared library · Rust / Cargo
CycloneDX 1.5 · 588 KB
TINL core library, shared by the service, the WASM build and the extension.
443 components · 444 dependency edges
Generated by cargo-cyclonedx 0.5.9
Licences: MIT OR Apache-2.0 (198), Apache-2.0 (129), MIT (41), Apache-2.0 OR MIT (34), CC0-1.0 (8), BSD-3-Clause (6)
sha256 59a0f256ab82c91ef1a037831e7706b40eb6c223b4f1b5c8e51fc9c0be9c7b09
TINL service · Service · Rust / Cargo
CycloneDX 1.5 · 701 KB
TINL workspace service binary.
532 components · 533 dependency edges
Generated by cargo-cyclonedx 0.5.9
Licences: MIT OR Apache-2.0 (231), Apache-2.0 (130), MIT (65), Apache-2.0 OR MIT (37), Unicode-3.0 (18), CC0-1.0 (8), 1 with no declared licence
sha256 c98c955c9b498358b9fa4638ac262d8065029223d2a942984c292cc5e6b2721c
TINL WASM · Distributed package · Rust / Cargo → WASM
CycloneDX 1.5 · 597 KB
The WASM build consumed by the browser extension and the wallet integrations.
450 components · 451 dependency edges
Generated by cargo-cyclonedx 0.5.9
Licences: MIT OR Apache-2.0 (204), Apache-2.0 (129), MIT (41), Apache-2.0 OR MIT (34), CC0-1.0 (8), BSD-3-Clause (6), 1 with no declared licence
sha256 03d61d05c639400da02a511d25346535e02cb8ba82fd9232c60ac8a6db0933ad
a3e9.com — container image · Shipped image · Container / Debian + Node.js
CycloneDX 1.7 · 5.3 MB
The shipped image for this site: the Node runtime, the installed node_modules and the Debian base packages. Reconciled by scanning rather than by a compiler-embedded graph — see the method note on its reconciliation record, which is a weaker claim and is labelled as one.
2,502 components · 109 dependency edges
Generated by syft 1.51.0
Licences: MIT (984), ISC (247), BSD-3-Clause (70), Apache-2.0 (64), BSD-2-Clause (34), BlueOak-1.0.0 (28), 963 with no declared licence
sha256 698fa50e2cc47cf0591fb2734a41c8bda4f72139066143502f4146802e6b04c0
a3e9.com · Website · Node.js / pnpm
CycloneDX 1.6 · 2.7 MB
This site. Included because a site that publishes supply-chain evidence and exempts itself from it is making an exception it has not argued for.
1,160 components · 1,160 dependency edges
Generated by cdxgen 12.8.3
Licences: MIT (757), ISC (119), Apache-2.0 (29), BSD-3-Clause (25), BSD-2-Clause (16), BlueOak-1.0.0 (15), 172 with no declared licence
sha256 39a067e05a4a7bea06095a58b78c6373ec93b3234a753610b88defb8e77876eb
// WHAT_THIS_IS_NOT
Read before citing these files
An SBOM is an inventory, not a clearance. These files record what each build resolved. They do not assert that the listed versions are free of known vulnerabilities, that their licences have been reviewed, or — except where a reconciliation below says otherwise — that a shipped binary was built from exactly this graph. Those are three separate claims, each needing its own evidence.
// RECONCILED_AGAINST_THE_IMAGE
a3e9-chain-router.cdx.json
The compiler embedded this graph into the shipped binary; it is compared to the published SBOM. Built with the private a3e9-audit-client dependency fetched from a local bare mirror rather than from GitHub, because no registry credential was available here. The mirror was at the identical pinned commit e2faa68ccbeb887dc4dd72fdcda7ee85e8e11ff2 that Cargo.toml and Cargo.lock name, and cargo still resolved it as a git dependency, so the resolved graph is the same as a credentialed build would produce. The fetch origin is the only difference and it is recorded here rather than left implicit.
a3e9-identity.cdx.json
The compiler embedded this graph into the shipped binary; it is compared to the published SBOM. Built with the private a3e9-audit-client dependency fetched from a local bare mirror rather than from GitHub, because no registry credential was available here. The mirror was at the identical pinned commit e2faa68ccbeb887dc4dd72fdcda7ee85e8e11ff2 that Cargo.toml and Cargo.lock name, and cargo still resolved it as a git dependency, so the resolved graph is the same as a credentialed build would produce. The fetch origin is the only difference and it is recorded here rather than left implicit.
a3e9-mpc-multiplexer.cdx.json
The compiler embedded this graph into the shipped binary; it is compared to the published SBOM.
a3e9-notary.cdx.json
The compiler embedded this graph into the shipped binary; it is compared to the published SBOM.
a3e9-rwa-evaluator.cdx.json
The compiler embedded this graph into the shipped binary; it is compared to the published SBOM.
a3e9-website.cdx.json
Two scanners compared. Shows the image contains the packages the SBOM lists; does NOT show the build consumed them.
Not reconciled, and why
a3e9-website
Its image was built and scanned, but the scan method does not yield a clean answer for a Node project and tuning it until it did would be dishonest. Of 1,160 published components 1,060 match; the ~200 differences are structural, not suspicious — 96 are platform-specific binaries the lockfile declares for other operating systems and this linux image correctly never installs, the rest are nested package manifests one scanner counts separately, duplicate transitive versions, and the vendored file: dependencies the two tools spell differently. The record is published with that breakdown rather than as a pass or a failure.
a3e9-audit-client
A pure library crate with no binaries and no Dockerfile. Nothing ships as an executable or an image, so there is no artifact to read a compiled dependency graph out of. For a library the published SBOM is the description of what is distributed.
a3e9-tinl-core
A library crate in the TINL workspace, which contains no Dockerfile. Same position as the audit client: no image, nothing compiled to compare against.
a3e9-tinl-service
Compiles to a binary, but the TINL workspace ships no Dockerfile, so no image exists to extract that binary from. Reconciling it needs a container build that does not exist yet, not a new technique.
a3e9-tinl-wasm
A WebAssembly module rather than an ELF executable. cargo-auditable writes its graph into an ELF section that WASM does not have, and the package is distributed to npm rather than in an image, so neither reconciliation method applies as written.
Limit
// VERIFY_IT
# 1. Fetch the manifest, its signature, and the key it is checked against. # The key is the same one that signs the CBOM — nothing new to trust. curl -sO https://a3e9.com/evidence/sbom/SBOM.sha256 curl -sO https://a3e9.com/evidence/sbom/SBOM.sha256.sig curl -sO https://a3e9.com/evidence/cbom_signing_key.pub # 2. Verify the signature over the manifest. Ed25519 over the 32 raw digest # bytes, exactly as on /evidence/cbom. HEX=$(grep -v '^#' cbom_signing_key.pub | tr -d '[:space:]') printf '302a300506032b6570032100%s' "$HEX" | xxd -r -p > pub.der openssl pkey -pubin -inform DER -in pub.der -out pub.pem sed -n '/^---BEGIN/,/^---END/p' SBOM.sha256.sig \ | grep -v '^---\|^cbom_sha256=\|^key_label=\|^signed_at=' \ | tr -d '\n' | base64 -d > sig.bin sha256sum SBOM.sha256 | cut -d' ' -f1 | xxd -r -p > digest.bin openssl pkeyutl -verify -pubin -inkey pub.pem -rawin -in digest.bin -sigfile sig.bin # -> Signature Verified Successfully # 3. Fetch the SBOMs the manifest names, then let coreutils check them. # The signature covers the manifest; the manifest covers the files. curl -sO https://a3e9.com/evidence/sbom/a3e9-notary.cdx.json sha256sum -c SBOM.sha256 --ignore-missing # 4. Read the graph. Plain CycloneDX JSON, no A3E9 tooling required. jq -r '.components[] | "\(.name) \(.version)"' a3e9-notary.cdx.json | sort | head
Use the spec version the file itself declares — passing v1_5 to a 1.6 document fails validation for a reason that has nothing to do with the document being wrong.
// WHAT_A_TOKEN_ADDS
These files record what a build resolved from a lockfile. A token lets you inspect the running evaluator image itself, which is the only way to check that what shipped matches what was resolved.
Everything above is checkable without contacting anyone, and is meant to be read first. The token exists because the remainder needs a provisioned environment — not because the evidence is being held back.