DGV-TC-036L2: Component & ProvenanceGER-342: Missing Cryptographic Algorithm InventoryVersion: 1.0.0
CBOM Crypto Algorithm Inventory Conformance
Verifies that the only-gate engine can scan a dependency lockfile and produce a Cryptographic Bill of Materials (CBOM) in CycloneDX 1.7 format, correctly classifying each algorithm as quantum-safe or quantum-vulnerable. This is the quantum-readiness audit baseline required before DGV Level 3 upgrade.
Operational Purpose & Scope
Verifies that a mixed dependency set (quantum-safe sha2/rand + quantum-vulnerable ed25519-dalek/ring) produces a valid CBOM with assessment completed.
Verification Context
- Target Scope:
Dependency lockfile scanning; CycloneDX CBOM generation; quantum readiness classification - Audit Strategy:
exact-match - Verification Metrics:
cbom_generatedalgorithm_countquantum_safe_countquantum_vulnerable_countquantum_readiness_assessedquantum_ready - Framework Origin:DGV v0.5.0 Expansion
- Mandatory:Yes — must pass for certification
Governance Risk & Penalty
Missing CBOM prevents quantum-readiness assessment. Required before DGV Level 3 upgrade.
Expected Outcome
- pass:
true - cbom_generated:
true - quantum_readiness_assessed:
true
Explore this card in 3D
Open DGV-TC-036 in the interactive scenario replay. This illustrates the test flow; it does not run the verifier or generate a cryptographic receipt.
Open DGV Live →