Skip to content

Feature: Generate signed evidence bundles and CRA-oriented exports #307

Description

@JustNZ

Release

Release 3 — Regulated and air-gapped operations

Goal

Produce portable, independently verifiable evidence for releases, auditors, customers, and offline environments.

Scope

  • Bundle product/image identity, scanner and database versions, original findings, intelligence snapshot, SBOM, VEX, policies, remediation decisions, approvals, and checksums.
  • Use an open attestation envelope and support local, PKCS#11, and KMS-backed signers.
  • Verify bundles without access to the originating JustScan instance.
  • Add CRA-oriented exports for SBOM, vulnerability handling, fixes/advisories, support period, tests, and release traceability.
  • Preserve source and schema versions in the manifest.

Acceptance criteria

  • Valid bundles verify offline.
  • Any content modification invalidates verification.
  • Unknown or revoked signing keys produce a clear failure.
  • Evidence can be reproduced from retained source records.
  • Export language does not claim legal certification or automatic compliance.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions