Skip to main content

In this article

SBOM Verification

Stable and PreRelease HVE Core releases publish Software Bill of Materials (SBOM) files in SPDX 2.3 JSON format. Per-artifact SBOMs describe each VSIX or plugin ZIP. dependencies.spdx.json describes the dependency tree used during the build.

What Gets Published

Each channel release publishes:

AssetChannelAttestation topology
<artifact>.spdx.jsonStable and PreReleaseSPDX predicate over its VSIX or ZIP subject
dependencies.spdx.jsonStable and PreReleaseSPDX predicate over each VSIX or ZIP subject
hve-core.openvex.jsonStable onlySeparate VEX subject attestation

The SBOM files are predicate payloads in the channel package workflows. They are not independently attested SPDX subjects. Stable additionally uses dependencies.spdx.json as the subject of an OpenVEX predicate.

Verifying the SBOM Attestation

SBOM attestation verification uses the GitHub CLI. Install it if you have not already:

# Windows (winget)
winget install GitHub.cli

# macOS (Homebrew)
brew install gh

Download assets from the exact channel tag:

# PreRelease
gh release download prerelease-v<version> -R microsoft/hve-core \
-p '*.vsix' -p '*.zip' -p '*.spdx.json'

# Stable
gh release download v<version> -R microsoft/hve-core \
-p '*.vsix' -p '*.zip' -p '*.spdx.json'

Verify SPDX predicates through their primary artifact subjects:

# Stable VSIX
gh attestation verify hve-core-<version>.vsix -R microsoft/hve-core \
--signer-workflow microsoft/hve-core/.github/workflows/extension-provenance.yml \
--predicate-type https://spdx.dev/Document/v2.3

# PreRelease VSIX
gh attestation verify hve-core-<version>.vsix -R microsoft/hve-core \
--signer-workflow microsoft/hve-core/.github/workflows/extension-provenance.yml \
--predicate-type https://spdx.dev/Document/v2.3

# Stable plugin ZIP
gh attestation verify <plugin-id>.zip -R microsoft/hve-core \
--signer-workflow microsoft/hve-core/.github/workflows/release-stable-publish.yml \
--predicate-type https://spdx.dev/Document/v2.3

# PreRelease plugin ZIP
gh attestation verify <plugin-id>.zip -R microsoft/hve-core \
--signer-workflow microsoft/hve-core/.github/workflows/release-prerelease.yml \
--predicate-type https://spdx.dev/Document/v2.3

These commands can match both the per-artifact and dependency SBOM attestations because both use the SPDX 2.3 predicate type. Inspect the returned attestation statements when you need to distinguish the predicate payloads.

Do not verify dependencies.spdx.json as an SPDX subject. On both channels it is an SPDX predicate payload over the primary package subjects. Stable also uses it as a subject for an OpenVEX predicate; PreRelease does not.

A successful verification confirms:

  • An SPDX predicate was attached to the selected primary artifact
  • The predicate was produced by the specified channel workflow
  • The attestation has not been modified since signing

TIP

Build provenance and SPDX predicates are independent attestations. Omit --predicate-type to verify build provenance. Use https://spdx.dev/Document/v2.3 to match SPDX predicates.

Downloading and Inspecting

Inspect a downloaded per-artifact SBOM:

jq '{
version: .spdxVersion,
name: .name,
created: .creationInfo.created,
packages: (.packages | length)
}' hve-core-<version>.vsix.spdx.json

# Package list with versions
jq '.packages[] | {name, versionInfo}' hve-core-<version>.vsix.spdx.json

# License information
jq '.packages[] | {name, licenseConcluded, licenseDeclared}' hve-core-<version>.vsix.spdx.json

Inspect dependencies.spdx.json as data while verifying its SPDX content through a primary VSIX or plugin ZIP subject:

jq '{
version: .spdxVersion,
name: .name,
created: .creationInfo.created,
packages: (.packages | length)
}' dependencies.spdx.json

Key SPDX Fields

The SBOM follows the SPDX 2.3 specification. These fields are most relevant for security and compliance review:

FieldDescription
spdxVersionSpecification version (SPDX-2.3)
nameDocument name identifying the scanned artifact
creationInfoTimestamp and tool that generated the document
packagesArray of components with name, version, and supplier
licenseConcludedLicense determined through analysis
licenseDeclaredLicense stated by the package author
relationshipsDependency graph between components

Consuming the SBOM

You can feed the SPDX JSON file into security and compliance tooling:

Use CaseDescription
Vulnerability scanningImport into tools like Grype, Trivy, or Dependabot to check for known CVEs in bundled components.
License complianceParse licenseConcluded and licenseDeclared fields to validate that all included licenses meet your organization's policy.
Inventory trackingUse the package list to maintain an accurate record of third-party components in your environment.
  • SECURITY.md: Build provenance verification and vulnerability reporting
  • Security Model: Security controls including SBOM attestation (SC-7)

🤖 Crafted with precision by ✨Copilot following brilliant human instruction, then carefully refined by our team of discerning human reviewers.