CycloneDX inventory
Generate a machine-readable package inventory for supported ISO and disk-image workflows.

Software supply chain
Keep the recipe, build record, artifact identity, CycloneDX inventory, and VM test results connected. Reviewers can see what was built and what was actually tested without relying on a release note alone.
OpenFactory generates a software inventory for supported Linux image builds and keeps artifact and verification records alongside the result. The workflow is designed to fail visibly when evidence is incomplete rather than silently labeling unknown packages as safe.
Generate a machine-readable package inventory for supported ISO and disk-image workflows.
Tie the inventory and verification record to the built output with stable identifiers and hashes.
Boot the produced image in a VM and retain the result of agreed functional or visual checks.
Preserve inventory coverage and unknown results so security reviewers can distinguish missing evidence from an unaffected package.
Each step contributes a different fact. Together they make a release review more concrete.
Version the Linux recipe and the validation expectations for the system.
Build the artifact, generate its CycloneDX sidecar, and record artifact identifiers and hashes.
Boot the actual result, run checks, and retain both passing and unresolved evidence for review.
No. OpenFactory makes inputs, artifacts, and checks reviewable, but does not market every image build as bit-for-bit deterministic.
Artifact hashes and hash-bound CycloneDX records are available today. Broader signing and external attestation claims are not presented as generally available.
No. The inventory and artifact evidence can support your review and scanner workflows. OpenFactory also performs supported advisory assessment, but specialist controls remain part of the customer security program.
Use one representative image to identify which evidence OpenFactory produces today and which controls still belong in your surrounding process.