Resources

Plain-English glossary.

Short explanations for people evaluating release evidence workflows without needing every implementation detail.

Release dossier verify-ready
01

Artifact digest

02

SBOM inventory

03

Vulnerability decision

04

Signed package

Terms

Evidence

Proof material around a software release: scan results, component lists, build records, vulnerability decisions, approvals, artifact hashes, release reports, and customer-safe files.

Evidence package

An organized bundle of release proof that can be reviewed internally or shared with a customer.

SBOM

A software ingredients list. It describes the components used inside software.

CVE

A public identifier for a known software flaw.

VEX

A structured way to explain whether a known vulnerability actually affects a specific product or release.

Customer-safe package

A package that contains useful review evidence without exposing unnecessary internal details.

Release readiness

A structured view of whether the release has expected evidence, decisions, approvals, and known limitations before it is shared or shipped.

Next step

Evaluate the technical truth on GitHub.

The website qualifies the business problem. The repository remains the source of truth for code, docs, release artifacts, limitations, and verification evidence.