A3E9 logoA3E9
// AUDIENCE_FILTERShowing content for NIST / standards conformance. De-emphasized: Competitive positioning, the industry-landscape framing, and on-chain market operations — none of it is conformance evidence.
All evidence

// SBOM · NO_LOGIN_REQUIRED

Every Dependency We Resolved, and Every Repository That Has None.

16 CycloneDX software bills of materials across 8 repositories, listing 9,610 resolved components with their versions, licences and dependency edges — signed as a set, and for one product checked against the binary that actually shipped. 5 in-scope repositories have no SBOM at all, and each one’s reason is stated below rather than left to be noticed.

// COVERAGE

What Is Covered, and What Is Not.

The programme scopes 13 repositories. 8 have at least one published SBOM; 5 do not. The absences are the informative half of this table — an inventory page listing only the repositories that went well is a brochure.
RepositoryEcosystemSBOM
a3e9-audit-clientRust / CargoPublished — 0 components
a3e9-chain-routerContainer / Debian + RustPublished — 2 products, 1,673 components
a3e9-identityContainer / Debian + RustPublished — 2 products, 890 components
a3e9-mpc-multiplexerContainer / Debian + RustPublished — 2 products, 623 components
a3e9-notaryContainer / Debian + RustPublished — 2 products, 799 components
a3e9-rwa-evaluatorContainer / Debian + RustPublished — 2 products, 538 components
a3e9-tinlRust / CargoPublished — 3 products, 1,425 components
a3e9-websiteContainer / Debian + Node.jsPublished — 2 products, 3,662 components
HSMC++ / MakeNone. The signing service publishes a CBOM rather than an SBOM today: its cryptographic inventory is generated from a source scan with a CI drift gate, but no dependency-graph generator has been run against its CMake and system-package inputs. The CBOM is the artifact under /evidence/cbom; it inventories cryptography, not packages.
a3e9-attestationC++ / MakeNone. Builds a runtime attestation artifact — a Merkle root over the loaded shared libraries, signed by the HSM and checked at daemon startup. That is evidence about a running process, not a CycloneDX dependency graph, and converting it would break the startup check that consumes it. A separate CycloneDX SBOM has not been generated yet.
a3e9-contractsFoundry / SolidityNone. Dependencies are pinned as git submodules rather than through a package lockfile, so the pin is a commit SHA and no off-the-shelf generator reads it. Assembling the SBOM from submodule state is straightforward and has not been done yet.
a3e9-evaluatorPython / CMake / DockerNone. No lock file exists — no requirements, pyproject, poetry or uv inputs to resolve. An SBOM generated from the source tree alone would describe intent rather than what a build installs, so the honest options are to resolve from the built image or to declare the gap. It is declared.
a3e9-ipDocumentsNone. Ships no software. Business and legal documents only, with nothing to build, package or install. Recorded here so the absence is a decision on the page rather than a repository that quietly went missing from it.

Limit

5 of 13 repositories have no dependency inventory published. Nothing on this page should be read as portfolio-wide coverage, and no claim of that kind is made anywhere on this site.

// DOWNLOAD

Every File, With Its Digest.

Plain CycloneDX JSON. No A3E9 tooling is needed to read or validate any of them, and the digest beside each one is the digest of the exact bytes behind its link. All 22 are covered by a single Ed25519 signature over SBOM.sha256, so the membership of this set is attested and not just its contents.
a3e9-audit-client.cdx.json

Audit client · Shared library · Rust / Cargo

CycloneDX 1.5 · 2 KB

Safe Rust wrapper over the HSM audit trail's C ABI, so services write into the same HMAC-chained trail rather than reimplementing the wire format.

0 components · 1 dependency edges

Generated by cargo-cyclonedx 0.5.9

sha256 6a285ca23c7dd55bac719f5d7f9e9e5d7e403d0d2952e8e142c5ad344fc27e20

a3e9-chain-router-image.cdx.json

Chain router — container image · Shipped image · Container / Debian + Rust

CycloneDX 1.7 · 2.1 MB

The shipped image for the chain router, including the Debian base packages the source-resolved SBOM does not cover. Built with its private dependency fetched from a local mirror at the pinned commit — see the reconciliation note.

1,093 components · 837 dependency edges

Generated by syft 1.51.0

Licences: BSD-3-Clause (30), GPL-2.0-only (19), BSD-2-Clause (10), Apache-2.0 (8), sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816 (4), BSD-4-Clause-UC (3), 987 with no declared licence

sha256 7b349b6eec0fa066b680580361801e6e574e68ca6cfeff913da0bddd9329d92b

a3e9-chain-router.cdx.json

Chain router · Service · Rust / Cargo

CycloneDX 1.5 · 754 KB

Routes signing requests across chains.

580 components · 581 dependency edges

Generated by cargo-cyclonedx 0.5.9

Licences: MIT OR Apache-2.0 (249), Apache-2.0 (121), MIT (77), Apache-2.0 OR MIT (53), Unicode-3.0 (18), CC0-1.0 (14)

sha256 907b47e60ac656d1fa0bdbda6cf696aeec3b002cd97b496151d84a0803408927

a3e9-identity-image.cdx.json

Identity service — container image · Shipped image · Container / Debian + Rust

CycloneDX 1.7 · 1.1 MB

The shipped image for the identity service, including the Debian base packages the source-resolved SBOM does not cover. Built with its private dependency fetched from a local mirror at the pinned commit — see the reconciliation note.

615 components · 443 dependency edges

Generated by syft 1.51.0

Licences: BSD-3-Clause (30), GPL-2.0-only (19), BSD-2-Clause (10), Apache-2.0 (8), sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816 (4), BSD-4-Clause-UC (3), 509 with no declared licence

sha256 cb6125aa85b0c7b20d4310eff0edaaefa4269d301fcd16c47d805fa76eaf99d5

a3e9-identity.cdx.json

Identity service · Service · Rust / Cargo

CycloneDX 1.5 · 339 KB

Identity and policy service.

275 components · 276 dependency edges

Generated by cargo-cyclonedx 0.5.9

Licences: MIT OR Apache-2.0 (155), MIT (42), Apache-2.0 OR MIT (28), Unicode-3.0 (18), MPL-2.0 (5), BSD-3-Clause (3)

sha256 b7e528d740dec82a4e805813eaf5dccd0b625bf4c91944154e53d4fc80f91c5b

a3e9-mpc-multiplexer-image.cdx.json

MPC multiplexer — container image · Shipped image · Container / Debian + Rust

CycloneDX 1.7 · 880 KB

The shipped image for the MPC multiplexer, including the Debian base packages the source-resolved SBOM does not cover.

429 components · 303 dependency edges

Generated by syft 1.51.0

Licences: BSD-3-Clause (30), GPL-2.0-only (19), BSD-2-Clause (10), Apache-2.0 (8), sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816 (4), BSD-4-Clause-UC (3), 323 with no declared licence

sha256 6f9fa2cd589238e73faf02be138e64700c6974d6452a5f48d67b966aeb43e8ff

a3e9-mpc-multiplexer.cdx.json

MPC multiplexer · Service · Rust / Cargo

CycloneDX 1.5 · 237 KB

Multiplexes MPC provisioning sessions.

194 components · 195 dependency edges

Generated by cargo-cyclonedx 0.5.9

Licences: MIT OR Apache-2.0 (95), MIT (38), Unicode-3.0 (18), Apache-2.0 OR MIT (14), Apache-2.0 (5), Apache-2.0 OR ISC OR MIT (4)

sha256 d530a9c3bb602730b429f25ae3c01a517e055aa7b7c1dda155ad4e6b5be92944

a3e9-notary-image.cdx.json

Notary — container image · Shipped image · Container / Debian + Rust

CycloneDX 1.7 · 1.0 MB

The whole shipped image, not just the Rust graph: the Debian base and its packages alongside the compiled binaries. Scanned from the built image by digest. This is the inventory that answers a CVE question about the OS layer, which the source-resolved SBOM covers none of.

543 components · 385 dependency edges

Generated by syft 1.51.0

Licences: BSD-3-Clause (30), GPL-2.0-only (19), BSD-2-Clause (10), Apache-2.0 (8), sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816 (4), BSD-4-Clause-UC (3), 437 with no declared licence

sha256 aa06f74db4a05625b2383ac3978d670e76441e279f6453e4b2edafeae1f5b423

a3e9-notary.cdx.json

Notary · Service · Rust / Cargo

CycloneDX 1.5 · 313 KB

Notarisation service.

256 components · 257 dependency edges

Generated by cargo-cyclonedx 0.5.9

Licences: MIT OR Apache-2.0 (126), MIT (41), Apache-2.0 OR MIT (40), Unicode-3.0 (18), Apache-2.0 (5), Apache-2.0 OR ISC OR MIT (3)

sha256 652edd4489c04f356ecd2859d923689d4566a6ccd4420b48ea1dfc0bf784a8ec

a3e9-rwa-evaluator-image.cdx.json

RWA evaluator — container image · Shipped image · Container / Debian + Rust

CycloneDX 1.7 · 694 KB

The shipped image for the RWA evaluator, including the Debian base packages the source-resolved SBOM does not cover.

315 components · 233 dependency edges

Generated by syft 1.51.0

Licences: BSD-3-Clause (30), GPL-2.0-only (19), BSD-2-Clause (10), Apache-2.0 (8), sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816 (4), BSD-4-Clause-UC (3), 209 with no declared licence

sha256 ddc4db2bcd1742706e29190a69e49909687a9e593031e7bcad6b26999890d4b7

a3e9-rwa-evaluator.cdx.json

RWA evaluator · Service · Rust / Cargo

CycloneDX 1.5 · 273 KB

Real-world-asset evaluation service.

223 components · 224 dependency edges

Generated by cargo-cyclonedx 0.5.9

Licences: MIT OR Apache-2.0 (124), MIT (38), Apache-2.0 OR MIT (21), Unicode-3.0 (18), ISC (3), Unlicense OR MIT (3)

sha256 1190df227e17d2a7309559fa4e697768b790a08a8dd39379e743e4820df1b654

a3e9-tinl-core.cdx.json

TINL core · Shared library · Rust / Cargo

CycloneDX 1.5 · 588 KB

TINL core library, shared by the service, the WASM build and the extension.

443 components · 444 dependency edges

Generated by cargo-cyclonedx 0.5.9

Licences: MIT OR Apache-2.0 (198), Apache-2.0 (129), MIT (41), Apache-2.0 OR MIT (34), CC0-1.0 (8), BSD-3-Clause (6)

sha256 59a0f256ab82c91ef1a037831e7706b40eb6c223b4f1b5c8e51fc9c0be9c7b09

a3e9-tinl-service.cdx.json

TINL service · Service · Rust / Cargo

CycloneDX 1.5 · 701 KB

TINL workspace service binary.

532 components · 533 dependency edges

Generated by cargo-cyclonedx 0.5.9

Licences: MIT OR Apache-2.0 (231), Apache-2.0 (130), MIT (65), Apache-2.0 OR MIT (37), Unicode-3.0 (18), CC0-1.0 (8), 1 with no declared licence

sha256 c98c955c9b498358b9fa4638ac262d8065029223d2a942984c292cc5e6b2721c

a3e9-tinl-wasm.cdx.json

TINL WASM · Distributed package · Rust / Cargo → WASM

CycloneDX 1.5 · 597 KB

The WASM build consumed by the browser extension and the wallet integrations.

450 components · 451 dependency edges

Generated by cargo-cyclonedx 0.5.9

Licences: MIT OR Apache-2.0 (204), Apache-2.0 (129), MIT (41), Apache-2.0 OR MIT (34), CC0-1.0 (8), BSD-3-Clause (6), 1 with no declared licence

sha256 03d61d05c639400da02a511d25346535e02cb8ba82fd9232c60ac8a6db0933ad

a3e9-website-image.cdx.json

a3e9.com — container image · Shipped image · Container / Debian + Node.js

CycloneDX 1.7 · 5.3 MB

The shipped image for this site: the Node runtime, the installed node_modules and the Debian base packages. Reconciled by scanning rather than by a compiler-embedded graph — see the method note on its reconciliation record, which is a weaker claim and is labelled as one.

2,502 components · 109 dependency edges

Generated by syft 1.51.0

Licences: MIT (984), ISC (247), BSD-3-Clause (70), Apache-2.0 (64), BSD-2-Clause (34), BlueOak-1.0.0 (28), 963 with no declared licence

sha256 698fa50e2cc47cf0591fb2734a41c8bda4f72139066143502f4146802e6b04c0

a3e9-website.cdx.json

a3e9.com · Website · Node.js / pnpm

CycloneDX 1.6 · 2.7 MB

This site. Included because a site that publishes supply-chain evidence and exempts itself from it is making an exception it has not argued for.

1,160 components · 1,160 dependency edges

Generated by cdxgen 12.8.3

Licences: MIT (757), ISC (119), Apache-2.0 (29), BSD-3-Clause (25), BSD-2-Clause (16), BlueOak-1.0.0 (15), 172 with no declared licence

sha256 39a067e05a4a7bea06095a58b78c6373ec93b3234a753610b88defb8e77876eb

// WHAT_THIS_IS_NOT

An Inventory, Not a Clearance.

The distinction decides what these files can be cited for, and it is the one most commonly elided on pages like this.

Read before citing these files

An SBOM is an inventory, not a clearance. These files record what each build resolved. They do not assert that the listed versions are free of known vulnerabilities, that their licences have been reviewed, or — except where a reconciliation below says otherwise — that a shipped binary was built from exactly this graph. Those are three separate claims, each needing its own evidence.

Build paths are redacted, deliberately

Both generators write the build host's absolute filesystem paths into every document — cargo into each workspace member's bom-ref, cdxgen into the resolved location of all 1,160 website packages. Those describe one developer's disk, not the software, so they are rewritten to repo-relative form before publication. Components, versions, licences and dependency edges are untouched. A reviewer regenerating locally will see different path strings for this reason and no other.

One product is reconciled against its shipped image. Ten are not.

Every SBOM here records what the resolver produced from a lockfile — a claim about a repository, not about an artifact. For 6 of 10 source products that claim has been checked against the shipped image, and for five of those against the dependency graph the compiler embedded into the binary itself. The rest remain source-resolved and unverified against any image, and should be read as exactly that.

Spec versions differ, and are recorded per file

The Rust SBOMs are CycloneDX 1.5 and the website's is 1.6, because that is the highest each generator emits — cargo-cyclonedx supports up to 1.5, cdxgen up to 1.6. Nothing is converted between versions: a conversion step would put a re-serialisation between what the generator observed and what is published. Each file states its own spec version and the page reads it from the file.

Signed — with the same development key, and the same caveat

One Ed25519 signature covers SBOM.sha256, and SBOM.sha256 covers all 22 artifacts, so adding, removing or altering any one of them invalidates it. It was made with the same SoftHSM2 development key that signs the CBOM: cryptographically valid, and an attestation of nothing an auditor should rely on. The envelope's key_label reads A3E9-ATTESTATION-KEY-PROD, which is the label the tool was asked to record and not evidence of which key signed. Treat it as change detection.

// RECONCILED_AGAINST_THE_IMAGE

Checked Against What Actually Shipped.

For a Rust binary the compiler embeds the dependency graph it resolved into the executable itself. That graph is read back out of the binary inside the shipped image and compared to the SBOM published here, which turns “this is what the lockfile said” into something checkable against the artifact. Where that is not possible the comparison is between two scanners instead, which is a weaker claim and is labelled as one on every record below.

a3e9-chain-router.cdx.json

compiler-attestedReconciled
image id
sha256:941624cd0b68f0be093769f60627ef5cacda6825633e4d498da96753fe6972fe
root crate
a3e9-chain-router@0.1.0 · matches SBOM metadata
in shipped image
580
published SBOM
580
matched
580
only in image
0
only in SBOM
0
OS packages in image
106 — not covered by the source SBOM

The compiler embedded this graph into the shipped binary; it is compared to the published SBOM. Built with the private a3e9-audit-client dependency fetched from a local bare mirror rather than from GitHub, because no registry credential was available here. The mirror was at the identical pinned commit e2faa68ccbeb887dc4dd72fdcda7ee85e8e11ff2 that Cargo.toml and Cargo.lock name, and cargo still resolved it as a git dependency, so the resolved graph is the same as a credentialed build would produce. The fetch origin is the only difference and it is recorded here rather than left implicit.

a3e9-identity.cdx.json

compiler-attestedReconciled
image id
sha256:af30a3219bfb818077a5fe0960a2b5a7eb3143e0491b7c47bc73b34426448d4a
root crate
a3e9-identity@0.1.0 · matches SBOM metadata
in shipped image
275
published SBOM
275
matched
275
only in image
0
only in SBOM
0
OS packages in image
106 — not covered by the source SBOM

The compiler embedded this graph into the shipped binary; it is compared to the published SBOM. Built with the private a3e9-audit-client dependency fetched from a local bare mirror rather than from GitHub, because no registry credential was available here. The mirror was at the identical pinned commit e2faa68ccbeb887dc4dd72fdcda7ee85e8e11ff2 that Cargo.toml and Cargo.lock name, and cargo still resolved it as a git dependency, so the resolved graph is the same as a credentialed build would produce. The fetch origin is the only difference and it is recorded here rather than left implicit.

a3e9-mpc-multiplexer.cdx.json

compiler-attestedReconciled
image id
sha256:a04b90e0f479b926afb69d45f3848ba46ebba7521f3d947043b4858ab3203d0f
root crate
a3e9-mpc-multiplexer@0.1.0 · matches SBOM metadata
in shipped image
194
published SBOM
194
matched
194
only in image
0
only in SBOM
0
OS packages in image
106 — not covered by the source SBOM

The compiler embedded this graph into the shipped binary; it is compared to the published SBOM.

a3e9-notary.cdx.json

compiler-attestedReconciled
image id
sha256:31b4e2da878dca76dc7fc7098e6137774083908cf658486980cb2cf4fcb3beec
root crate
a3e9-notary@0.1.0 · matches SBOM metadata
in shipped image
256
published SBOM
256
matched
256
only in image
0
only in SBOM
0
OS packages in image
106 — not covered by the source SBOM

The compiler embedded this graph into the shipped binary; it is compared to the published SBOM.

a3e9-rwa-evaluator.cdx.json

compiler-attestedReconciled
image id
sha256:b008d9edef32a42a13354410df3faca33891813a10e0bcc67bea1fb4e9a9ab32
root crate
a3e9-rwa-evaluator@0.1.0 · matches SBOM metadata
in shipped image
223
published SBOM
223
matched
223
only in image
0
only in SBOM
0
OS packages in image
106 — not covered by the source SBOM

The compiler embedded this graph into the shipped binary; it is compared to the published SBOM.

a3e9-website.cdx.json

scanner-comparedDifferences found
image id
sha256:84b9407215096ddf60c7d012e67192d809e60f28a15934c86a198c31f1c192e1
root crate
· matches SBOM metadata
in shipped image
1161
published SBOM
1160
matched
1060
only in image
pkg:npm/%40a3e9/tinl-wasm-node@0.1.0, pkg:npm/%40a3e9/tinl-wasm@0.1.0, pkg:npm/%40hookform/resolvers%2Fajv@1.0.0, pkg:npm/%40hookform/resolvers%2Farktype@2.0.0, pkg:npm/%40hookform/resolvers%2Fclass-validator@1.0.0, pkg:npm/%40hookform/resolvers%2Fcomputed-types@1.0.0, pkg:npm/%40hookform/resolvers%2Feffect-ts@1.0.0, pkg:npm/%40hookform/resolvers%2Ffluentvalidation-ts@1.0.0, pkg:npm/%40hookform/resolvers%2Fio-ts@1.0.0, pkg:npm/%40hookform/resolvers%2Fjoi@1.0.0, pkg:npm/%40hookform/resolvers%2Fnope@1.0.0, pkg:npm/%40hookform/resolvers%2Fstandard-schema@1.0.0, pkg:npm/%40hookform/resolvers%2Fsuperstruct@1.0.0, pkg:npm/%40hookform/resolvers%2Ftypanion@1.0.0, pkg:npm/%40hookform/resolvers%2Ftypebox@1.0.0, pkg:npm/%40hookform/resolvers%2Ftypeschema@1.0.0, pkg:npm/%40hookform/resolvers%2Fvalibot@1.0.0, pkg:npm/%40hookform/resolvers%2Fvest@1.0.0, pkg:npm/%40hookform/resolvers%2Fvine@1.0.0, pkg:npm/%40hookform/resolvers%2Fyup@1.0.0, pkg:npm/%40hookform/resolvers%2Fzod@1.0.0, pkg:npm/1to2@1.0.0, pkg:npm/a3e9-website@1.0.0, pkg:npm/ansi-regex@6.2.2, pkg:npm/beep-boop@1.2.3, pkg:npm/benchmark@1.0.0, pkg:npm/brace-expansion@2.0.2, pkg:npm/dom-helpers/activeElement, pkg:npm/dom-helpers/addClass, pkg:npm/dom-helpers/addEventListener, pkg:npm/dom-helpers/animate, pkg:npm/dom-helpers/animationFrame, pkg:npm/dom-helpers/attribute, pkg:npm/dom-helpers/camelize, pkg:npm/dom-helpers/camelizeStyle, pkg:npm/dom-helpers/canUseDOM, pkg:npm/dom-helpers/childElements, pkg:npm/dom-helpers/childNodes, pkg:npm/dom-helpers/clear, pkg:npm/dom-helpers/closest, pkg:npm/dom-helpers/collectElements, pkg:npm/dom-helpers/collectSiblings, pkg:npm/dom-helpers/contains, pkg:npm/dom-helpers/css, pkg:npm/dom-helpers/filterEventHandler, pkg:npm/dom-helpers/getComputedStyle, pkg:npm/dom-helpers/getScrollAccessor, pkg:npm/dom-helpers/hasClass, pkg:npm/dom-helpers/height, pkg:npm/dom-helpers/hyphenate, pkg:npm/dom-helpers/hyphenateStyle, pkg:npm/dom-helpers/insertAfter, pkg:npm/dom-helpers/isDocument, pkg:npm/dom-helpers/isInput, pkg:npm/dom-helpers/isTransform, pkg:npm/dom-helpers/isVisible, pkg:npm/dom-helpers/isWindow, pkg:npm/dom-helpers/listen, pkg:npm/dom-helpers/matches, pkg:npm/dom-helpers/nextUntil, pkg:npm/dom-helpers/offset, pkg:npm/dom-helpers/offsetParent, pkg:npm/dom-helpers/ownerDocument, pkg:npm/dom-helpers/ownerWindow, pkg:npm/dom-helpers/parents, pkg:npm/dom-helpers/position, pkg:npm/dom-helpers/prepend, pkg:npm/dom-helpers/querySelectorAll, pkg:npm/dom-helpers/remove, pkg:npm/dom-helpers/removeClass, pkg:npm/dom-helpers/removeEventListener, pkg:npm/dom-helpers/scrollLeft, pkg:npm/dom-helpers/scrollParent, pkg:npm/dom-helpers/scrollTo, pkg:npm/dom-helpers/scrollTop, pkg:npm/dom-helpers/scrollbarSize, pkg:npm/dom-helpers/siblings, pkg:npm/dom-helpers/text, pkg:npm/dom-helpers/toggleClass, pkg:npm/dom-helpers/transitionEnd, pkg:npm/dom-helpers/triggerEvent, pkg:npm/dom-helpers/width, pkg:npm/exponential-backoff@3.1.2, pkg:npm/glob@10.4.5, pkg:npm/ip-address@10.0.1, pkg:npm/isexe@3.1.1, pkg:npm/minimatch@9.0.5, pkg:npm/minipass-flush@1.0.5, pkg:npm/node-gyp@11.1.0, pkg:npm/p-map@7.0.3, pkg:npm/react-transition-group/CSSTransition, pkg:npm/react-transition-group/ReplaceTransition, pkg:npm/react-transition-group/SwitchTransition, pkg:npm/react-transition-group/Transition, pkg:npm/react-transition-group/TransitionGroup, pkg:npm/react-transition-group/TransitionGroupContext, pkg:npm/react-transition-group/config, pkg:npm/semver@7.7.2, pkg:npm/socks@2.8.7, pkg:npm/strip-ansi@7.1.2, pkg:npm/v8-compile-cache@2.4.0
only in SBOM
pkg:generic/a3e9_tinl_wasm_bg.wasm?path=%40a3e9/tinl-wasm/a3e9_tinl_wasm_bg.wasm, pkg:npm/%40a3e9%2Ftinl-wasm-node?vcs_url=file%3Avendor/tinl-wasm, pkg:npm/%40a3e9%2Ftinl-wasm?vcs_url=file%3Avendor/tinl-wasm-web, pkg:npm/%40cdxgen/cdxgen-plugins-bin-darwin-amd64@2.5.1, pkg:npm/%40cdxgen/cdxgen-plugins-bin-darwin-arm64@2.5.1, pkg:npm/%40cdxgen/cdxgen-plugins-bin-linux-arm64@2.5.1, pkg:npm/%40cdxgen/cdxgen-plugins-bin-linux-arm@2.5.1, pkg:npm/%40cdxgen/cdxgen-plugins-bin-linux-ppc64@2.5.1, pkg:npm/%40cdxgen/cdxgen-plugins-bin-linuxmusl-arm64@2.5.1, pkg:npm/%40cdxgen/cdxgen-plugins-bin-windows-amd64@2.5.1, pkg:npm/%40cdxgen/cdxgen-plugins-bin-windows-arm64@2.5.1, pkg:npm/%40cdxgen/safer-exec-darwin-amd64@0.15.0, pkg:npm/%40cdxgen/safer-exec-darwin-arm64@0.15.0, pkg:npm/%40cdxgen/safer-exec-linux-arm64@0.15.0, pkg:npm/%40esbuild/aix-ppc64@0.21.5, pkg:npm/%40esbuild/aix-ppc64@0.25.10, pkg:npm/%40esbuild/android-arm64@0.21.5, pkg:npm/%40esbuild/android-arm64@0.25.10, pkg:npm/%40esbuild/android-arm@0.21.5, pkg:npm/%40esbuild/android-arm@0.25.10, pkg:npm/%40esbuild/android-x64@0.21.5, pkg:npm/%40esbuild/android-x64@0.25.10, pkg:npm/%40esbuild/darwin-arm64@0.21.5, pkg:npm/%40esbuild/darwin-arm64@0.25.10, pkg:npm/%40esbuild/darwin-x64@0.21.5, pkg:npm/%40esbuild/darwin-x64@0.25.10, pkg:npm/%40esbuild/freebsd-arm64@0.21.5, pkg:npm/%40esbuild/freebsd-arm64@0.25.10, pkg:npm/%40esbuild/freebsd-x64@0.21.5, pkg:npm/%40esbuild/freebsd-x64@0.25.10, pkg:npm/%40esbuild/linux-arm64@0.21.5, pkg:npm/%40esbuild/linux-arm64@0.25.10, pkg:npm/%40esbuild/linux-arm@0.21.5, pkg:npm/%40esbuild/linux-arm@0.25.10, pkg:npm/%40esbuild/linux-ia32@0.21.5, pkg:npm/%40esbuild/linux-ia32@0.25.10, pkg:npm/%40esbuild/linux-loong64@0.21.5, pkg:npm/%40esbuild/linux-loong64@0.25.10, pkg:npm/%40esbuild/linux-mips64el@0.21.5, pkg:npm/%40esbuild/linux-mips64el@0.25.10, pkg:npm/%40esbuild/linux-ppc64@0.21.5, pkg:npm/%40esbuild/linux-ppc64@0.25.10, pkg:npm/%40esbuild/linux-riscv64@0.21.5, pkg:npm/%40esbuild/linux-riscv64@0.25.10, pkg:npm/%40esbuild/linux-s390x@0.21.5, pkg:npm/%40esbuild/linux-s390x@0.25.10, pkg:npm/%40esbuild/netbsd-arm64@0.25.10, pkg:npm/%40esbuild/netbsd-x64@0.21.5, pkg:npm/%40esbuild/netbsd-x64@0.25.10, pkg:npm/%40esbuild/openbsd-arm64@0.25.10, pkg:npm/%40esbuild/openbsd-x64@0.21.5, pkg:npm/%40esbuild/openbsd-x64@0.25.10, pkg:npm/%40esbuild/openharmony-arm64@0.25.10, pkg:npm/%40esbuild/sunos-x64@0.21.5, pkg:npm/%40esbuild/sunos-x64@0.25.10, pkg:npm/%40esbuild/win32-arm64@0.21.5, pkg:npm/%40esbuild/win32-arm64@0.25.10, pkg:npm/%40esbuild/win32-ia32@0.21.5, pkg:npm/%40esbuild/win32-ia32@0.25.10, pkg:npm/%40esbuild/win32-x64@0.21.5, pkg:npm/%40esbuild/win32-x64@0.25.10, pkg:npm/%40rollup/rollup-android-arm-eabi@4.52.4, pkg:npm/%40rollup/rollup-android-arm64@4.52.4, pkg:npm/%40rollup/rollup-darwin-arm64@4.52.4, pkg:npm/%40rollup/rollup-darwin-x64@4.52.4, pkg:npm/%40rollup/rollup-freebsd-arm64@4.52.4, pkg:npm/%40rollup/rollup-freebsd-x64@4.52.4, pkg:npm/%40rollup/rollup-linux-arm-gnueabihf@4.52.4, pkg:npm/%40rollup/rollup-linux-arm-musleabihf@4.52.4, pkg:npm/%40rollup/rollup-linux-arm64-gnu@4.52.4, pkg:npm/%40rollup/rollup-linux-arm64-musl@4.52.4, pkg:npm/%40rollup/rollup-linux-loong64-gnu@4.52.4, pkg:npm/%40rollup/rollup-linux-ppc64-gnu@4.52.4, pkg:npm/%40rollup/rollup-linux-riscv64-gnu@4.52.4, pkg:npm/%40rollup/rollup-linux-riscv64-musl@4.52.4, pkg:npm/%40rollup/rollup-linux-s390x-gnu@4.52.4, pkg:npm/%40rollup/rollup-openharmony-arm64@4.52.4, pkg:npm/%40rollup/rollup-win32-arm64-msvc@4.52.4, pkg:npm/%40rollup/rollup-win32-ia32-msvc@4.52.4, pkg:npm/%40rollup/rollup-win32-x64-gnu@4.52.4, pkg:npm/%40rollup/rollup-win32-x64-msvc@4.52.4, pkg:npm/%40tailwindcss/oxide-android-arm64@4.1.14, pkg:npm/%40tailwindcss/oxide-darwin-arm64@4.1.14, pkg:npm/%40tailwindcss/oxide-darwin-x64@4.1.14, pkg:npm/%40tailwindcss/oxide-freebsd-x64@4.1.14, pkg:npm/%40tailwindcss/oxide-linux-arm-gnueabihf@4.1.14, pkg:npm/%40tailwindcss/oxide-linux-arm64-gnu@4.1.14, pkg:npm/%40tailwindcss/oxide-linux-arm64-musl@4.1.14, pkg:npm/%40tailwindcss/oxide-wasm32-wasi@4.1.14, pkg:npm/%40tailwindcss/oxide-win32-arm64-msvc@4.1.14, pkg:npm/%40tailwindcss/oxide-win32-x64-msvc@4.1.14, pkg:npm/fsevents@2.3.3, pkg:npm/lightningcss-darwin-arm64@1.30.1, pkg:npm/lightningcss-darwin-x64@1.30.1, pkg:npm/lightningcss-freebsd-x64@1.30.1, pkg:npm/lightningcss-linux-arm-gnueabihf@1.30.1, pkg:npm/lightningcss-linux-arm64-gnu@1.30.1, pkg:npm/lightningcss-linux-arm64-musl@1.30.1, pkg:npm/lightningcss-win32-arm64-msvc@1.30.1, pkg:npm/lightningcss-win32-x64-msvc@1.30.1
OS packages in image
100 — not covered by the source SBOM

Two scanners compared. Shows the image contains the packages the SBOM lists; does NOT show the build consumed them.

Not reconciled, and why

a3e9-website

Its image was built and scanned, but the scan method does not yield a clean answer for a Node project and tuning it until it did would be dishonest. Of 1,160 published components 1,060 match; the ~200 differences are structural, not suspicious — 96 are platform-specific binaries the lockfile declares for other operating systems and this linux image correctly never installs, the rest are nested package manifests one scanner counts separately, duplicate transitive versions, and the vendored file: dependencies the two tools spell differently. The record is published with that breakdown rather than as a pass or a failure.

a3e9-audit-client

A pure library crate with no binaries and no Dockerfile. Nothing ships as an executable or an image, so there is no artifact to read a compiled dependency graph out of. For a library the published SBOM is the description of what is distributed.

a3e9-tinl-core

A library crate in the TINL workspace, which contains no Dockerfile. Same position as the audit client: no image, nothing compiled to compare against.

a3e9-tinl-service

Compiles to a binary, but the TINL workspace ships no Dockerfile, so no image exists to extract that binary from. Reconciling it needs a container build that does not exist yet, not a new technique.

a3e9-tinl-wasm

A WebAssembly module rather than an ELF executable. cargo-auditable writes its graph into an ELF section that WASM does not have, and the package is distributed to npm rather than in an image, so neither reconciliation method applies as written.

Limit

6 of the 10 source-resolved SBOMs have been checked against a shipped image; 5 have not, for the reasons listed directly above. The images were built here, not pulled from a registry a customer receives from — so this demonstrates that the toolchain and the comparison work, not that a distributed release matches. Two of the gaps are a missing credential and would close with access; the rest are artifacts that ship no image at all, and waiting will not change them.

// VERIFY_IT

Check a Digest, Read a Graph.

Nothing below needs A3E9 software. The validate step uses the upstream CycloneDX CLI against a schema we do not control, which is the point.
# 1. Fetch the manifest, its signature, and the key it is checked against.
#    The key is the same one that signs the CBOM — nothing new to trust.
curl -sO https://a3e9.com/evidence/sbom/SBOM.sha256
curl -sO https://a3e9.com/evidence/sbom/SBOM.sha256.sig
curl -sO https://a3e9.com/evidence/cbom_signing_key.pub

# 2. Verify the signature over the manifest. Ed25519 over the 32 raw digest
#    bytes, exactly as on /evidence/cbom.
HEX=$(grep -v '^#' cbom_signing_key.pub | tr -d '[:space:]')
printf '302a300506032b6570032100%s' "$HEX" | xxd -r -p > pub.der
openssl pkey -pubin -inform DER -in pub.der -out pub.pem
sed -n '/^---BEGIN/,/^---END/p' SBOM.sha256.sig \
  | grep -v '^---\|^cbom_sha256=\|^key_label=\|^signed_at=' \
  | tr -d '\n' | base64 -d > sig.bin
sha256sum SBOM.sha256 | cut -d' ' -f1 | xxd -r -p > digest.bin
openssl pkeyutl -verify -pubin -inkey pub.pem -rawin -in digest.bin -sigfile sig.bin
# -> Signature Verified Successfully

# 3. Fetch the SBOMs the manifest names, then let coreutils check them.
#    The signature covers the manifest; the manifest covers the files.
curl -sO https://a3e9.com/evidence/sbom/a3e9-notary.cdx.json
sha256sum -c SBOM.sha256 --ignore-missing

# 4. Read the graph. Plain CycloneDX JSON, no A3E9 tooling required.
jq -r '.components[] | "\(.name) \(.version)"' a3e9-notary.cdx.json | sort | head

Use the spec version the file itself declares — passing v1_5 to a 1.6 document fails validation for a reason that has nothing to do with the document being wrong.

// WHAT_A_TOKEN_ADDS

These files record what a build resolved from a lockfile. A token lets you inspect the running evaluator image itself, which is the only way to check that what shipped matches what was resolved.

Everything above is checkable without contacting anyone, and is meant to be read first. The token exists because the remainder needs a provisioned environment — not because the evidence is being held back.