# Distribution Evidence

Managed documentation for Distribution Evidence.

# Distribution Profile

<!-- BOOKSTACK-DOCUMENT-RELEASE:BEGIN -->
# Distribution Profile

| Field | Value |
| --- | --- |
| Distribution | BSS — OpenSOF |
| Product | OpenSOF |
| Release | 0.15.1 |
| Deployment | `opensof.bss.dev` |
| Source | `/srv/bss/releases/OpenSOF-v0.15.0-20app` |
| Evidence | Static release scan |
| Source fingerprint | `cda583b42f2a0d296b268ab5b174932a378c8be6fb52ffa1af14af896e990f6e` |
| Status | Generated baseline — human review required |

> **Verification boundary:** This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.

## Edition identity

| Property | Value |
| --- | --- |
| Edition code | `bss-opensof` |
| Organization | BSS |
| Product brand | OpenSOF |
| Primary deployment | `opensof.bss.dev` |
| Documentation language | en |
| Release source | `/srv/bss/releases/OpenSOF-v0.15.0-20app` |
| Source fingerprint | `cda583b42f2a0d296b268ab5b174932a378c8be6fb52ffa1af14af896e990f6e` |

## Edition boundary

This edition is maintained independently. URLs, service names, environment variables, branding, included modules, language and release history must be verified here rather than copied blindly from another OpenC5ISR/OpenSOF distribution.
<!-- BOOKSTACK-DOCUMENT-RELEASE:END -->

---

## Maintainer Notes

<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-BEGIN -->
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-END -->

# Evidence and Confidence

<!-- BOOKSTACK-DOCUMENT-RELEASE:BEGIN -->
# Evidence and Confidence

| Field | Value |
| --- | --- |
| Distribution | BSS — OpenSOF |
| Product | OpenSOF |
| Release | 0.15.1 |
| Deployment | `opensof.bss.dev` |
| Source | `/srv/bss/releases/OpenSOF-v0.15.0-20app` |
| Evidence | Generator methodology |
| Source fingerprint | `cda583b42f2a0d296b268ab5b174932a378c8be6fb52ffa1af14af896e990f6e` |
| Status | Generated baseline — human review required |

> **Verification boundary:** This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.

## Evidence classes

| Class | Meaning |
| --- | --- |
| Catalog baseline | Product intent supplied by the maintained component catalog. |
| Static release evidence | Names, routes, configuration, manifests and declarations found in readable files. |
| Host evidence | Relevant readable systemd and Nginx configuration found on the machine. |
| Runtime verification | A test executed against the live deployment. This generator does not perform it automatically. |

## Known limitations

- This is static evidence extracted from files and readable host configuration; it is not runtime certification.
- Dynamic routes, generated configuration, secrets stores, databases, and inaccessible files may not appear.
- Potential credentials are intentionally redacted and raw source content is not copied into the report.

## Review rule

Do not turn a candidate route, service or component into an authoritative promise until it has been exercised in the named release. Record the command, expected result, actual result, date and reviewer in Maintainer Notes or the relevant acceptance-test page.
<!-- BOOKSTACK-DOCUMENT-RELEASE:END -->

---

## Maintainer Notes

<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-BEGIN -->
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-END -->