CS Code buyer evidence pack

Demo App 2.0.0

Release evidence for restricted, offline and controlled software deployments. Generated locally from scanner outputs and structured for customer security review.

4
Services
1
Exposed ports
2
Excluded files
4
SBOM components
0
Vulnerabilities

Executive Summary

This pack provides release evidence for Demo App 2.0.0, generated from local scan outputs.

It covers 4 detected service(s), 1 exposed port mapping(s), 11 environment variable reference(s), 7 potential external endpoint reference(s), and 4 SBOM component(s).

Current risk posture: Change review. Deployment-relevant changes are present and should be reviewed by security/operations.

The pack is designed for buyer security and operations review; it is not a replacement for customer-specific penetration testing, code review, accreditation or deployment acceptance.

0
Critical findings
0
High findings
7
Endpoint references
Change review

Deployment-relevant changes are present and should be reviewed by security/operations.

What This Pack Proves

  • The CLI can generate this evidence pack without the SaaS dashboard.
  • The pack records detected services, exposed ports, environment variable names, endpoint references, dependency posture and vulnerability posture.
  • Generated metadata and scanner/report artefacts include SHA-256 checksums so the receiver can verify covered evidence has not changed in transit.
  • Standard dashboard upload is metadata-only and excludes source code, project files, raw scanner reports, full file inventories and release ZIPs.
  • Update-diff evidence highlights deployment-relevant changes between release packs.

Approval Considerations

  • 1 new service(s), 0 removed service(s).
  • 1 added port mapping(s), 1 removed port mapping(s).
  • 3 added environment variable(s), 1 removed environment variable(s).
  • 6 added endpoint reference(s), 3 removed endpoint reference(s).
  • 3 added component(s), 2 removed component(s).
  • 0 new vulnerability finding(s), 2 resolved finding(s).

Services

ServiceImageBuild contextPorts
weblocal build.8081:80
workerpython:3.12-slim
telemetryalpine:3.20
dockerfilelocal build.

Ports

ServiceMappingSource
web8081:80docker-compose.yml

Environment Variables

Names and sources only. Secret values are not captured in this evidence pack.

NameSourceFileServiceValue captured
API_BASE_URLdocker_compose_environmentdocker-compose.ymlwebNo
STRIPE_KEYdocker_compose_environmentdocker-compose.ymlwebNo
QUEUE_NAMEdocker_compose_environmentdocker-compose.ymlworkerNo
TELEMETRY_ENDPOINTdocker_compose_environmentdocker-compose.ymltelemetryNo
API_BASE_URLenv_file.env.exampleNo
STRIPE_KEYenv_file.env.exampleNo
DATABASE_URLenv_file.env.exampleNo
FEATURE_TELEMETRYenv_file.env.exampleNo
OIDC_AUTHORITYenv_file.env.exampleNo
API_BASE_URLvariable_patterndocker-compose.ymlNo
STRIPE_KEYvariable_patterndocker-compose.ymlNo

Scanner Exclusions

Files intentionally excluded before local evidence summaries were generated. Default sensitive exclusions include real environment files and key material; .env.example remains eligible for variable-name detection.

PathSourcePattern
.env.localdefault_sensitive_exclude.env.local
secrets/runtime.envdefault_sensitive_excludesecrets/**

External Endpoints

Potential endpoint references for reviewer triage. Context is redacted for common token/secret patterns.

TermFileLineContext
https://.env.example1API_BASE_URL=https://api.vendor.example/v2
https://.env.example5OIDC_AUTHORITY=https://login.microsoftonline.com/demo-tenant/v2.0
https://config/app.yml2issuer: https://login.microsoftonline.com/demo-tenant/v2.0
https://config/app.yml3license_endpoint: https://license.vendor.example/check
https://config/app.yml4telemetry: https://telemetry.vendor.example/collect
https://docker-compose.yml10API_BASE_URL: ${API_BASE_URL:-https://api.vendor.example/v2}
https://docker-compose.yml19TELEMETRY_ENDPOINT: https://telemetry.vendor.example/collect

SBOM Summary

4
Total components
ok

SBOM status

2
Ecosystems
1
Licence groups
ComponentVersionEcosystemLicence
fastapi0.115.14pypiunknown
pydantic-settings2.10.1pypiunknown
requests2.33.0pypiunknown
/home/arctic/cs-code-packagemanager/examples/demo-compose-app-v2/requirements.txtnot specifiedfileunknown

Vulnerability Summary

0
Critical
0
High
0
Medium
0
Low

No top vulnerability findings reported.

Update Diff

This section highlights changes between release packs when a diff is attached.

ChangeComponent
Added/home/arctic/cs-code-packagemanager/examples/demo-compose-app-v2/requirements.txt | | file
Addedpydantic-settings | 2.10.1 | pypi
Addedrequests | 2.33.0 | pypi
Removed/home/arctic/cs-code-packagemanager/examples/demo-compose-app-v1/requirements.txt | | file
Removedrequests | 2.32.3 | pypi

Integrity And Checksums

SHA-256 checksums cover generated metadata, scanner reports, summaries, policy results and update diffs. Self-referential evidence exports and ZIP containers are excluded. Run cscode checksums PACK_PATH --verify against the received pack to detect changed or missing files.

19
Files checksummed
SHA-256

Hash algorithm

FileCategorySizeSHA-256
README.mdbuyer-evidence2287ada3e4c104c6bc7dbee1e19a3d6b1b68b39ff6c4d2b4d4c40fc1c351536d036e
environment-variables.jsonmetadata2077a72ca9691b850d3cf9da463e232eea6824ec945e79d105c0ded43da1c5d9e135
excluded-files.jsongenerated-artifact6271893424a12169aaf8c54879436e902475a9399ee7260d909c150b71c996c595f
excluded-files.mdgenerated-artifact435425ab5aa256ebd078a8d56a877ad6d0800ed52805e4c8288f006eae0004581a8
external-endpoints.jsonmetadata14375267f6a9df586de8f9ea62063b91e5b9ca3295e0a2e19f9dd914f15614eefefd
files-scanned.jsonmetadata779d9129c108ef54c96916911af41351397ba291eb53fd7cc25a70e30bf2c9eea3c
ports.jsonmetadata12295b9b4d6bd374386f2ab7b70671e7970a91a9eb327ccdfb54066d47da7c3d236
release-diff.jsonbuyer-evidence2134f32a70e1bf3e18b5e3b88afde04c659a629b1fd9c380cfc483512aae2865f3d8
release-diff.mdbuyer-evidence1866919d193a74007e32f5fecc28a02ff3876a35d8ad8a70910bc5e2e3f62b6161be
release-manifest.jsonmetadata10922ef25aa50c8dd515ccd07adae729c8de62b79d0d33225c4a9acdfc10d468891c
sbom/images/telemetry-alpine-3.20.cyclonedx.jsonsbom50939395485e26b6c2edb10f37b5d85737a53c90139f4619189ae77556afb8accd365
sbom/images/worker-python-3.12-slim.cyclonedx.jsonsbom9383472dfd90c1f05ea9a51f4ffb2b9e8b52aa0b780f23a0e053391bd89b768def33bb
sbom/sbom-summary.jsonsbom64694420a6c7d7ee0dcecd88d89250e0e00a99f040922f87aa78ccf6fd5971d74e4e70
sbom/sbom.cyclonedx.jsonsbom6545bc0fba562bd925338d417446f04263e16005f54b2ba949ff344e917050c36400
scan-summary.jsonmetadata60372761ff251e6122f3364d81cbdae1e9dbf0c0ac32ce2659089cb2565b7c02805
security/vulnerability-report.jsonvulnerability-reporting5687946e8ecc44c03ba3cf0f9d927a31ce4790bbdc293939ee391e2fdc8fe911e4a4
security/vulnerability-summary.jsonvulnerability-reporting24745d32d4437a31ca2baa8d30a8eba65758eb014bb681c6630ebd2b6de65d2a678
security/vulnerability-summary.mdvulnerability-reporting138b44d9f7e9f6f18b6a17bc267a46bbbc5dacad0e6bf0cf8787b25bb56e4d220e6
services.jsonmetadata8437949238a13cec146a62b98b4ed5b5deb6ab23895432b02585a3309485cec44ca

Install Guide

  1. Confirm Docker Engine and Docker Compose are installed on the target host.
  2. Copy this release pack and the approved release artefacts to the restricted deployment environment.
  3. Load container images from the approved offline image bundle. Image bundle generation remains a customer-specific step in this MVP.
  4. Create or update the deployment `.env` file using the environment variable list in this pack.
  5. Run `docker compose up -d` from the approved release directory. Compose env files referenced: .env.example.
  6. Verify service health using the product health endpoint or the buyer-approved operational checklist.

Rollback Guide

  1. Stop the current release using the buyer-approved service stop procedure.
  2. Restore the previous approved release pack and deployment artefacts.
  3. Restore previous environment/configuration files from the approved backup.
  4. Load the previous container image bundle if images are not already available locally.
  5. Start the previous release with the approved Docker Compose command.
  6. Verify service health and record rollback approval notes.

Known Limitations

  • Scanner results are limited to files available at scan time and the scanner tools/databases installed locally.
  • External endpoint detection is conservative and flags potential references for review; it is not a network egress proof.
  • Environment variable evidence lists names and sources, not secret values.
  • Container image loading, operational health checks and site-specific deployment approvals must be attached by the vendor or buyer team.

Recommended Next Actions

  • Review endpoint, environment variable and port changes with security/operations before deployment.
  • Attach buyer-specific install, health-check and rollback evidence before formal acceptance.
  • Record approval notes, exceptions and reviewer identity in the release workflow.
  • Review newly added components for licence/security acceptability.

Generated Artefacts Appendix

Artefact
README.md
checksums.json
checksums.md
environment-variables.json
evidence-pack.html
evidence-pack.md
excluded-files.json
excluded-files.md
external-endpoints.json
files-scanned.json
ports.json
release-diff.json
release-diff.md
release-manifest.json
sbom/images/telemetry-alpine-3.20.cyclonedx.json
sbom/images/worker-python-3.12-slim.cyclonedx.json
sbom/sbom-summary.json
sbom/sbom.cyclonedx.json
scan-summary.json
security/vulnerability-report.json
security/vulnerability-summary.json
security/vulnerability-summary.md
services.json