Release
Release 3 — Regulated and air-gapped operations
Goal
Produce portable, independently verifiable evidence for releases, auditors, customers, and offline environments.
Scope
- Bundle product/image identity, scanner and database versions, original findings, intelligence snapshot, SBOM, VEX, policies, remediation decisions, approvals, and checksums.
- Use an open attestation envelope and support local, PKCS#11, and KMS-backed signers.
- Verify bundles without access to the originating JustScan instance.
- Add CRA-oriented exports for SBOM, vulnerability handling, fixes/advisories, support period, tests, and release traceability.
- Preserve source and schema versions in the manifest.
Acceptance criteria
- Valid bundles verify offline.
- Any content modification invalidates verification.
- Unknown or revoked signing keys produce a clear failure.
- Evidence can be reproduced from retained source records.
- Export language does not claim legal certification or automatic compliance.
Release
Release 3 — Regulated and air-gapped operations
Goal
Produce portable, independently verifiable evidence for releases, auditors, customers, and offline environments.
Scope
Acceptance criteria