Skip to content

v0.8: audit receipts + CycloneDX/SARIF/report exports - #3

Merged
codehippie1 merged 1 commit into
mainfrom
release/v0.8
May 28, 2026
Merged

codehippie1 merged 1 commit into
mainfrom
release/v0.8

Conversation

@codehippie1

Copy link
Copy Markdown
Contributor

Summary

  • Ed25519 hash-chained audit receipts (burnwall audit seal / verify) — tamper-evident, metadata-only proof of every forwarded/blocked action. Each receipt stores a SHA-256 of the source row's contents, chained into the previous receipt, and signed with a local key. verify re-derives each hash from the live rows, so edits/deletions/reorders of a receipt or a sealed row are detected, and the chain can't be forged without the key. Seal-on-demand, off the proxy hot path.
  • CycloneDX 1.6 AI Bill of Materials (burnwall audit aibom).
  • SARIF 2.1.0 export of security blocks (burnwall audit sarif) for GitHub code scanning.
  • burnwall report (text/json/csv) + burnwall audit export (json/csv).

All metadata-only and read-only over the existing request/security logs — never reads prompt content.

Test plan

  • 389 tests pass (new in-crate seal/verify/tamper/wrong-key + aibom/sarif unit tests; audit CLI integration tests)
  • cargo fmt + cargo clippy --all-targets -- -D warnings clean
  • Manual end-to-end: blocked a real request through the proxy, sealed + verified the chain, rendered sarif/report/aibom

Audit & compliance, local-first and metadata-only:

- audit seal/verify: Ed25519 hash-chained receipts over the request +
  security logs. Each receipt stores a SHA-256 of the source row's canonical
  contents, chained as hash = SHA-256(prev_hash || content_hash) and signed
  with a local key (~/.burnwall/audit_ed25519.key, 0600, generated on first
  use). verify re-derives every content hash from the live rows, so edits,
  deletions, or reorders of a receipt or a sealed row are detected, and the
  chain cannot be forged without the key. Seal-on-demand keeps it off the
  proxy hot path.
- audit aibom: CycloneDX 1.6 AI Bill of Materials for the window.
- audit sarif: security blocks as SARIF 2.1.0 for GitHub code scanning.
- report + audit export: shareable summary (text/json/csv) and receipt dump.

New audit_receipts table (UNIQUE(source, source_id), idempotent seal). Deps:
ed25519-dalek + rand_core. 389 tests pass; manually verified end-to-end (a
blocked request sealed + verified, sarif/report/aibom rendered).
@codehippie1
codehippie1 merged commit 01eee5a into main May 28, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant