🔒All inputs are processed locally in your browser. Nothing is transmitted, stored, or logged. Inputs disappear when you close the tab.

OCG-Industries Showcase · Cluster 13 Machine, AI and Software Integrity

SBOM Provenance
Attestation

Enter an SBOM descriptor alongside its attestation descriptor, and this tool checks whether the two are bound to the same subject, whether the predicate type and builder identity are stated, and whether the component count is positive. It counts the binding faults across those checks and recomputes a fingerprint of the attestation fields you entered. Signed is your own assertion; this tool does not verify a cryptographic signature.

Data: SPDX 2.3 · CycloneDX 1.6 · SLSA v1.0 · OpenVEX specification

SBOM Descriptor STEP 1
Number of components listed in the SBOM
The digest the SBOM describes
Attestation Descriptor STEP 2
The digest the attestation covers
The stated builder identity for the attestation
Status
--
Attested, unbound subject, or incomplete
Binding Faults
--
Out of 5 checks
Attestation Fingerprint
--
Mutation detector, not a cryptographic digest
Detail
SBOM format--
SBOM component count--
Subject bound--
Predicate stated--
Builder stated--
Component count positive--
Signed (self-asserted)--
Binding faults--
Attestation digest--
Status--
Policy Mandate v2.0 · what is this?