Skip to content

feat: Create Signed Evidence Bundles and Append-Only Transparency Log #1019

Description

@Mosas2000

Area

Evidence, reports, and compliance

Problem

Report hashes and source metadata do not provide a portable, independently verifiable proof of exactly which raw observations, code/config versions, and chain evidence produced a report.

Scope

Create signed evidence bundles containing canonical inputs, Merkle commitments, finality metadata, decoder versions, query parameters, derived outputs, and signer rotation metadata. Publish an append-only transparency log with inclusion and consistency proofs.

Acceptance criteria

  • A verifier can validate a bundle offline without trusting the application database.
  • Any changed input or output invalidates the signature/commitment.
  • Key rotation and revocation are represented in the log.
  • Bundles support partial disclosure while preserving proof validity.
  • REST and PDF exports link to the exact evidence root.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardThird CampaignCampaign: Third CampaignenhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions