leaf-parser
Maintainer, version, checksum, and license pinned together before the artifact leaves the greenhouse.
software bill of materials field institute
A public wall for tracing packages, hashes, licenses, maintainers, and the roots beneath every artifact.
Inventory is not a spreadsheet. It is a provenance specimen, pinned while the ink is still drying.
Repository, commit, signer, and declared intent are gathered before the build begins.
Tools, environments, and generated artifacts are annotated like cuts through a trunk.
The SBOM connects what shipped to what was observed, signed, and preserved.
risk greenhouse
Vulnerable versions, missing maintainers, unverifiable hashes, and absent licenses are marked with rust halos so the living inventory can be cut back before it climbs the wall.
study ledger
Collect every component as evidence, not decoration.
Bind source, build, hash, and signer until the chain can be retraced.
Keep the label with the specimen after the release leaves the shelf.
Mark uncertainty plainly so repair can begin in daylight.