Skip to content

Glossary

Add new terms in alphabetical order by section.

Repo: Executable verification of finite mathematical core of SE-210

SE-210 Paper: Operational Identity: A Finite Audit of Declared and Implemented Rules of Sameness.

Research Sites

Arxiv ("archive"): An open-access repository of scientific pre-prints. Arxiv.

OSF (Open Science Framework) Preprints: An open source software project that facilitates open collaboration in science research OSF Preprints.

SSRN (Social Science Research Network): An open access research platform repository for sharing early-stage research and preprints. SSRN.

Formal Verification & SE-210 Core

Divergence Witness: A finite pair of records $(r_0, r_1)$ for which the audited operational surface diverges under a relation classified by the supplied SE-210 regime.

The witness establishes nonconformance relative to that formalized regime; the validity of the regime's mapping to the external system commitment must be justified independently.

Operational Surface ($s$): The system mechanism or function whose inputs and outputs are observed to determine execution treatment.

Record ($r$) / Domain ($R$): Atomic entities within a finite domain whose operational behavior and identity lineage are tracked across system surfaces.

Regime ($\tau$): A declared classification mapping history edge families to equivalence classes (e.g., content identity preservation).

Vulnerability & Supply Chain Standards

CISA (Cybersecurity and Infrastructure Security Agency) is an operational agency of the United States Department of Homeland Security (DHS) established to act as the nation's cyber defense agency. CISA leads the national effort to understand, manage, and reduce risk to cyber and physical infrastructure, working closely with federal, state, local, and private-sector partners to secure critical systems, share threat intelligence, and establish guidelines (such as software supply chain and Software Bill of Materials or SBOM standards). CISA.

A CVE (Common Vulnerabilities and Exposures) is a publicly known cybersecurity flaw that has been cataloged and given a unique identification number. Managed by the MITRE Corporation and funded by the US Department of Homeland Security, the CVE program acts as a universal dictionary for software vulnerabilities. This ensures that security professionals, software vendors, and scanning tools (like Grype and Trivy) are all talking about the same security flaw when they use its ID.

PURL (Package URL): A standardized string specification used to identify and locate packages across ecosystems.

SBOM (Software Bill of Materials): The formal inventory of components and dependencies in a software artifact. These can be created for every GitHub repository. Analogous to a list of ingredients on food packaging, it inventories operating system packages, open-source libraries, plugins, extensions, and dependencies present within an application or container. This transparency allows scanning tools to instantly map components against known flaw repositories without analyzing the underlying source code. SBOMs are standardizing security compliance, following frameworks like CycloneDX or SPDX to ensure interoperability across different software ecosystems and platforms. They decouple inventory tracking from risk assessment, allowing organizations to generate a component snapshot once and retroactively query it as new vulnerabilities emerge.

SCA (Software Composition Analysis) are tools that inventory software components to find known, publicly disclosed vulnerabilities (like CVEs) embedded in dependencies.

VEX (Vulnerability Exploitability Exchange): A companion attestation (often from the vendor) indicating whether a declared vulnerability is exploitable in a given operational context.

Vulnerability Scanners & Analysis Tools

Anchore Grype Scanner: An open-source vulnerability scanner designed for container images and filesystems. It specializes in scanning an image or directory to find known vulnerabilities (CVEs) across operating system packages (like Alpine, Ubuntu, Red Hat) and language-specific dependencies (like Python, Ruby, Java, Node.js). Grype does one thing exceptionally well: matching software components against vulnerability databases.

  • Grype works with Syft (Anchore component inventory tool). Syft scans an image to inventory everything inside it (the SBOM), and Grype reads the SBOM to check for vulnerabilities.
  • It downloads a highly compressed vulnerability database locally, allowing it to scan images in seconds inside a CI/CD pipeline or a local terminal.
  • Grype uses sophisticated matching logic that accounts for vendor "backporting" (when OS maintainers patch a vulnerability in an older package version without changing the major version number), which prevents a lot of noisy, incorrect alerts.
  • It can scan Docker/OCI images, local directories, tarball archives, and SBOM files.

Aqua Security Trivy: An open-source, all-in-one security scanner for container and cloud-native environments.

  • Goes beyond vulnerability scanning to detect IaC misconfigurations, hardcoded secrets, and license compliance issues.
  • Operates natively with standard SBOM formats (SPDX, CycloneDX) without external dependencies.
  • Pulls from a centralized cloud database (Trivy DB) updating every six hours.