Software Bill of Materials (SBOM)

Status: not yet produced. No SBOM or provenance attestation exists today. The control is SBOM-PROVENANCE-001 in the Trust Center control table, where it reads Limited.

Our SBOM and build-provenance pipeline is implemented and committed (.github/workflows/attestations.yml), but it triggers only on a vX.Y.Z release tag, and no release tag has been cut yet. Nothing has been generated, signed, or published so far. This page describes what will be available at the first tagged release — not something you can download now.

What the pipeline will produce

Artifact Format How it will be produced
Dependency SBOM CycloneDX JSON (sbom.cdx.json) anchore/sbom-action (syft) over the repository, on every vX.Y.Z tag, in the attestations.yml CI workflow.
Build-provenance attestations in-toto / SLSA, Sigstore-signed GitHub actions/attest-build-provenance for the API + edge Worker bundles and for the SBOM itself; recorded in the public transparency log.

How to obtain the SBOM

Our source repository is private, so we will not point you at a repository URL you cannot open. When the first release is tagged, we will publish the signed SBOM for direct download from this page, together with the digest needed to verify it against the transparency log.

Until then, request the current dependency inventory at security@preferium.com and we will send it directly.

How to verify provenance

GitHub’s attestation tooling cryptographically verifies that a given Worker bundle (or the SBOM) was built by our pipeline, from our source, untampered:

gh attestation verify <artifact> --repo Preferium-AS/preferium-edge

Verification against a private source repository requires access GitHub does not grant anonymously. We will publish the verification path that works for external auditors alongside the first signed SBOM.

How we will preserve the chain of custody

The canonical SBOM is the signed, attested artifact produced by the release pipeline. When we publish it here, we will serve the signed artifact itself together with its digest, so the copy you download is the one the pipeline attested — not a detached, unverifiable re-export.

Questions about our supply-chain posture: security@preferium.com.