Skip to content
oleg-vdvPublic

About

No description, website, or topics provided.

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

18 Commits

Folders and files

Repository files navigation

ProofByte

Vanta proves your processes. ProofByte proves your bytes.

ProofByte is a technical-evidence engine for the 2027–2028 regulatory wave: it scans your actual code, containers and runtime, and produces machine-verifiable, auditor-ready artifacts — not questionnaires.

Packs

Pack Status Regulatory driver
pqc-radar — cryptographic inventory (CBOM) + post-quantum migration plan 🚧 v0 US EO 14412, CNSA 2.0 (2027), UK NCSC (2028), EU PQC transition (from 2026)
agent-trace — AI-agent inventory + tamper-evident action-log verification 🚧 v0 EU AI Act Art. 12 (high-risk deadline 2027-12-02), Kazakhstan AI Law 230-VIII

Quick start

npx @proofbyte/pqc-radar scan ./my-repo --cbom cbom.json --report report.md --sarif findings.sarif

agent-trace inventories the agents a codebase declares (MCP server configs, agent-framework imports, workflow files) and independently verifies a hash-chained action log — the evidence an auditor asks for when the question is "what did the agent actually do":

npx proofbyte-agent-trace scan ./my-repo --out agents.json
npx proofbyte-agent-trace verify ./journal.jsonl
npx proofbyte-agent-trace evidence --inventory agents.json --journal journal.jsonl --report evidence.md

The verifier is deliberately a separate implementation from the writer: proof that only its own author can check is not proof. The package's test suite verifies a journal produced by a Python writer.

pqc-radar walks your repository, detects quantum-vulnerable cryptography (RSA, ECC/ECDSA/ECDH, DH, DSA, Curve25519, legacy hashes, weak TLS configs) and emits:

  • cbom.json — a CycloneDX 1.6 Cryptographic Bill of Materials, the artifact regulators and auditors ask for;
  • report.md — a human-readable findings report with a prioritized migration plan (ML-KEM / FIPS 203, ML-DSA / FIPS 204, hybrid TLS);
  • findings.sarif — a SARIF 2.1.0 log for GitHub code scanning or any SARIF viewer.

Fast: hashicorp/vault (4 827 files) scans in ~9 s, node-forge in ~0.7 s — see real-world corpus results, regenerated weekly in CI, and the honest benchmark vs PQCA CBOMkit (spoiler: they're complementary — CBOMkit goes deeper on Java/Python, pqc-radar covers the whole polyglot estate).

Language coverage (v0): Java/Kotlin/Scala, Python, JavaScript/TypeScript, Go, C#, Rust, Ruby, PHP, C/C++, plus nginx/Apache TLS configs and certificate/keystore file discovery.

Live TLS endpoint check

npx @proofbyte/pqc-radar scan-tls your-api.example.com github.com:443

One handshake per host (no data sent) reports the negotiated protocol, cipher, key-exchange group and certificate key — and whether the endpoint already speaks hybrid post-quantum key exchange (X25519+ML-KEM-768) or is still harvest-now-decrypt-later exposed. Unknown groups are reported as inconclusive, never as findings.

CI gate — one line via the GitHub Action

- uses: oleg-vdv/proofbyte@v1
  with:
    fail-on-findings: 'true'

Or with plain npx:

- run: npx @proofbyte/pqc-radar scan . --sarif findings.sarif --fail-on-findings
- uses: github/codeql-action/upload-sarif@v3
  if: always()
  with:
    sarif_file: findings.sarif

Add the badge to show your repo is scanned:

[![PQC-scanned](https://img.shields.io/badge/PQC-scanned-2ea44f?logo=github)](https://github.com/oleg-vdv/proofbyte)

Security

The code scanner is fully offline (no network calls), has zero runtime dependencies, never modifies scanned code, skips symlinks, and only writes the output files you name. scan-tls is the one network feature: it connects only to endpoints you explicitly list and sends no payload beyond the TLS handshake. See SECURITY.md.

Status & roadmap

v0 uses fast line-pattern detection. Absence of findings is not proof of absence. Planned: PQCA CBOMkit engine integration for deep AST analysis, container/TLS endpoint collectors, signed artifacts.

Development

npm install
npm run build
npm test

Golden-fixture tests live in packages/pqc-radar/test/fixtures — small repos with deliberately planted crypto; every scanner change is verified against them. CI also dogfoods: the repo scans itself on every push.

Read more

License

MIT

About

No description, website, or topics provided.

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages