NODE-CONSTANT//SRF-14 · VEINHARDEN
WICK / 04//45.5°N · 73.5°W
← SURFACES/SRF-14HARDEN
Core Verification

Vein

Every dependency. Every CVE. Formally proven.

Formal supply chain analysis for software bills of materials. Vein parses CycloneDX and SPDX SBOMs, cross-references every component against live CVE databases, and applies Z3 formal analysis to fetched source code. Every finding is a proven constraint violation — not a scanner heuristic.

SBOM
CycloneDX + SPDX
OSV
CVE Database
Z3
Source Proof
§ SPECIFICATION
Input
  • CycloneDX or SPDX SBOM (JSON)
  • Optional: source URLs per component
  • Optional: private advisory feed
Constraints Verified
  • Component version vs. known CVE ranges (OSV API)
  • Integer overflow in C dependencies
  • Null pointer dereference paths
  • Format string injection in transitive deps
Output
  • CVE findings per component with severity + fix version
  • Z3 proof artifacts on fetched source
  • Wick-compatible artifact JSON per component
  • Aggregated supply chain risk report
§ SAMPLE PROOF ARTIFACT
ARTIFACT // VEIN-OPENSSL-01FAILURE DETECTED
// SAMPLE PROOF — VEIN ENGINE

OpenSSL 3.0.7 — CVE-2022-3786 detected in SBOM scan

TargetCycloneDX SBOM — openssl@3.0.7
Conditionversion = 3.0.7 → CVE-2022-3786 (CRITICAL) unfixed
VerdictSAT
SummaryCritical stack overflow in X.509 certificate verification. Fixed in 3.0.8. SBOM scan flagged before deployment.
StatusReview-ready
→ View full artifact repository
§ FIELD VALIDATION
#TargetVulnerability ClassStatus
01OpenSSL 3.0.x
Critical CVE
Critical CVEDetected + Fixed
02libcurl SBOM
Integer Overflow
Integer OverflowZ3 Proof
Run Vein on your system.

Formal engagement starts with a technical intake. We scope, configure, and deliver a proof artifact within the agreed SLA.

Request Briefing →