Adversarial test scorecard
Adversarial lab coverage demonstrates engineering robustness only. It is not a security assurance, not a certification, and not evidence of legal or CRA conformity.
This page describes SBOMFlow 0.4.0. The current build is 0.5.0. The run recorded here was executed against an earlier revision of the repository, at the version and revision recorded under The run below, and it has not been re-run since. No adversarial-laboratory run has been recorded for 0.5.0, and none is simulated here: a page that showed numbers for a run that never happened would be a fabricated measurement, so this page keeps the run it actually has. What it establishes is what that earlier run found, at that revision. What it does not establish is the behaviour of the current build, and it is not evidence about 0.5.0 in either direction — neither that the findings still hold nor that they were fixed. How the 0.5.0 build itself was checked before it was handed to anyone is a separate record, in the trust centre.
Every number on this page is generated from a recorded lab run. Nothing is typed in by hand, and a drift guard fails the build if this page and the recorded run disagree.
The run
- As of
- 2026-07-03T12:00:00Z (pinned reference date, not the execution time — the snapshot carries none, so the artifact stays reproducible; the version and revision below are the freshness signals)
- Tier
- standard
- Result
- pass
- Offline
- True
- Seed
- 20260703
- SBOMFlow version
- 0.4.0
- Repository revision
a514f59ca353bd775be04b3d2e68d8988b47922a
Cases by area
| Area | Cases | Passed | Failed |
|---|---|---|---|
| customer-isolation | 1 | 1 | 0 |
| determinism | 1 | 1 | 0 |
| identity-accuracy | 8 | 8 | 0 |
| launch-readiness | 3 | 3 | 0 |
| license-accuracy | 1 | 1 | 0 |
| release-gate | 10 | 10 | 0 |
| resilience | 10 | 10 | 0 |
| security-redaction | 10 | 10 | 0 |
| usability-contracts | 8 | 8 | 0 |
| vulnerability-accuracy | 9 | 9 | 0 |
| Total | 61 | 61 | 0 |
Determinism
This recorded run used ONE repetition, so it did not measure whether repeated runs produce byte-identical artifacts. The digest below covers the artifacts of that single run. The laboratory supports repeated-run comparison; this snapshot simply does not contain one.
- Artifacts digested
- 44
- Cross-repetition byte identity
- not measured — this run used a single repetition
- Basis
- audit(--as-of pinned, fixed probe path per invocation)
Mutation self-checks
Deliberate faults injected to prove the lab can actually fail. A suite that never fails when the product breaks is not evidence.
- Executed
- True
- Controls detected
- 4
Budget
- Observed duration
- 65.1s
- Tier budget
- 900s
- Within budget
- True
Known gaps
What this run did not establish. Recorded because a scorecard that only lists wins is marketing, not evidence.
- This recorded run did not list a known gap. That is not evidence that no product or laboratory gaps exist.
Capability coverage
56 of 56 capabilities recorded in the lab's coverage matrix are implemented and exercised by at least one named case. The matrix records the capabilities this lab tracks; it is not a claim that it enumerates everything a given product needs.
- Annex II user-information draft UNSIGNED discipline (347)2 cases
- BSI TR-03183-2 SBOM field presence1 case
- CSV formula-injection neutralization1 case
- Conan/vcpkg manifests under hostile shapes (323/324)3 cases
- HTML renderer injection escaping1 case
- NTIA field-presence check1 case
- advisory lifecycle (withdrawn/rejected/disputed)2 cases
- air-gapped install-then-audit lane (383; release tier)2 cases
- approvals workflow1 case
- audit-chain tamper detection1 case
- binary-to-package join under conflicting DBs + hostile ELF bytes (317/320)2 cases
- certification-harness sabotage (readiness gate cannot be gamed; 425)2 cases
- compiled-distribution (binary/wheel artifact parity)2 cases
- composition from lockfiles/manifests2 cases
- concurrent-run locking2 cases
- config channel equivalence + precedence (file/env/flag, 373)1 case
- cp4-warn-wiring (expired warns, never blocks, artifacts identical)2 cases
- cross-OS byte-determinism axes (397; hash seed, locale/TZ, creation order)1 case
- customer-view share profile redaction1 case
- decision-file merge without lost updates (357/421)2 cases
- deterministic canonical artifacts2 cases
- distro-backport labeling is context, never suppression (336)2 cases
- entitlement-issuance (forgery/tamper rejected, no key leak)2 cases
- eval-entitlement (gates no functionality)2 cases
- expanded design-partner release simulation (424 capstone)1 case
- external-scanner ingest correlates, never merges (345/346)2 cases
- gate replay vs recorded outcome (differential oracle, 359/371)2 cases
- historical release backfill (declared provenance)1 case
- hostile filenames / symlink non-escape1 case
- hostile-filesystem-conditions (ENOSPC/read-only/EACCES)4 cases
- imported SBOM trust boundary2 cases
- license-expression torture (depth cap, unknown-id storm; 311-315)1 case
- malformed input warns, never silent3 cases
- match dispute vs VEX vs version basis stay distinct (358/344)3 cases
- no overclaim / conformity language1 case
- offline default (network tripwire)2 cases
- operating-scenario matrix truthfulness (covered rows re-proven by running their commands; 436)2 cases
- post-release advisory re-evaluation (recheck)1 case
- range-accurate matching (versions/ranges wired live)3 cases
- release gate blocking + suppression2 cases
- release history + drift1 case
- resolved-Kconfig storms: duplicates, contradictions, comments (326/327/334)3 cases
- reviewer VEX boundary (valid vs invalid justification)2 cases
- revocation-flow (tamper/absent degrade, never block)2 cases
- schema-freeze bite (a mutated frozen stable key trips the guard; 427)2 cases
- secret hygiene / no credential leak1 case
- self-SBOM dogfooding1 case
- sharing-pack README verification drill (390)1 case
- sharing/auditor bundles1 case
- soak + memory budgets as nightly-tier gates (423/400)3 cases
- supplier intake under attack (declared-only, contact-free, contained; 168)2 cases
- supplier-facing VEX authoring (OpenVEX/CSAF/CycloneDX)1 case
- theme + empty-state + CSP surface sweep (385/387/388/395)1 case
- update-channel (manifest tamper warns, offline tripwire)2 cases
- vendored-header lookalike storm (319/420)2 cases
- vulnerability matching (sample feed)2 cases
This page describes engineering testing only. It is not an audit, not a certification, and not a statement about any specific product's regulatory position. How we run this laboratory is documented in the trust centre; the scoring discipline for the engine itself lives on the Evidence Assurance Benchmark.