Skip to content

Cybersecurity Dependency Inventory

Status: Controlled dependency inventory accepted within the Build 843 cybersecurity scope Owner: Software Developer Last updated: 2026-09-08

1. Purpose

Record the current software-composition baseline visible from the checked-in BionicLoop project and local package manifests.

This inventory is a controlled dependency snapshot. The exact-freeze composition and manual-advisory companion now exists at 2026-08-21-ide-freeze-sbom-advisory-manual.

Build 843 requires CryptoSwift 1.10.0 exactly, tracks the app-workspace resolution, and uses a fail-closed checker to enforce source, version, and revision. Historical exact-freeze dependency details remain in the Freeze Execution Report and its referenced evidence; this inventory presents the current controlled build composition. The Build 843 machine-readable source is Cybersecurity_SBOM_Build_843.cdx.json, with the dated review boundary in Technical Appendix A08B.

2. Scope of This Snapshot

Included here:

  • BionicLoop app project dependency surfaces visible in the checked-in BionicLoop.xcodeproj
  • local embedded packages and subprojects shipped with the app baseline
  • remote SwiftPM packages resolved for Build 843, plus their source requirements in local manifests and projects
  • binary algorithm artifact referenced by the app/core baseline

Operational follow-through:

  • retain required third-party acknowledgments with the distributed materials
  • continue vulnerability monitoring during the study; the controlled manual advisory method and its limitations are accepted under D09

3. Current Dependency Snapshot

3.1 First-party / repo-local components in the app baseline

Component Integration Form Current Baseline Evidence Notes
BionicLoop app target First-party app target BionicLoop.xcodeproj/project.pbxproj Primary shipped controller application.
BionicLoopCore Local Swift package BionicLoop.xcodeproj/project.pbxproj, BionicLoopCore/Package.swift Local core domain/runtime package referenced through XCLocalSwiftPackageReference.
LoopKit Local Swift package BionicLoop.xcodeproj/project.pbxproj, LoopKit/Package.swift Local package referenced through XCLocalSwiftPackageReference.
G7SensorKit / G7SensorKitUI Local embedded subproject/framework BionicLoop.xcodeproj/project.pbxproj references G7SensorKit.xcodeproj; upstream https://github.com/LoopKit/G7SensorKit; MIT license verified from upstream LICENSE on 2026-09-03; traced sync base 624bb360c277c43daa5232df986de7467bc0b72b Integrated as a checked-in local Xcode subproject rather than a remote package. The monorepo does not contain the upstream license file; provenance and license identity are recorded here without asserting current-tree identity to upstream HEAD.
OmniBLE Local embedded subproject/framework BionicLoop.xcodeproj/project.pbxproj references OmniBLE.xcodeproj Integrated as a checked-in local Xcode subproject rather than a remote package.
Algo2015.xcframework Local binary artifact BionicLoop.xcodeproj/project.pbxproj, BionicLoopCore/Package.swift Binary algorithm artifact referenced from Algo2015/build/Algo2015.xcframework.
Algo2015Bridge Local bridge target BionicLoopCore/Package.swift Repo-local bridge between host Swift code and Algo2015 binary artifact.
Algo2015Safety.xcframework Local binary artifact BionicLoopCore binary-target declaration and the controlled safety build/identity process Symbol-isolated safety-controller artifact; the controlled identity report records its relationship to the primary algorithm compilation.
Algo2015SafetyBridge Local bridge target BionicLoopCore/Package.swift Repo-local bridge between host Swift code and the isolated safety binary.

3.2 Remote SwiftPM dependencies observed at freeze

Package Source Resolved Version / Revision Evidence Current Use Surface
CryptoSwift https://github.com/krzyzanowskim/CryptoSwift 1.10.0 / f2a627b84c1ff96f21ac2fcb623ab36142dd5512 Build 843 tracked resolution and dependency verification Used by OmniBLE cryptographic/session paths; exact source, version, and revision are checked before build.
SlideButton https://github.com/no-comment/SlideButton branch main at 5eacebba4d7deeb693592bc9a62ab2d2181e133b (1.3.0) Formal-run console and captured resolution Used for slider-style controls. Branch requirement remains unpinned by the tag.
SwiftCharts https://github.com/ivanschuetz/SwiftCharts branch master at c354c1945bb35a1f01b665b22474f6db28cba4a2 Formal-run console, captured resolution, LoopKit/Package.swift Used through LoopKitUI; upstream states the project is no longer maintained. Branch requirement remains unpinned by the tag.

3.3 External regulatory context and non-reliance

The FDA 510(k) summary for Tidepool Loop, K203689, records that Tidepool evaluated known use problems from DIY Loop, adapted its design, and performed detailed verification and validation under the interoperable automated glycemic-controller requirements. This provides general regulatory context for bringing software with DIY Loop origins under formal design controls.

That clearance is not verification of BionicLoop's exact OmniBLE or G7SensorKit source, local modifications, or Build 843 device interfaces. No component-equivalence or inherited-verification claim is made. BionicLoop relies on the controlled Build 843 source and its own requirements, risk management, configuration controls, verification, and supporting real-device observations. See the FDA Tidepool Loop 510(k) summary.

4. Current Observations

  • The app project itself currently uses local BionicLoopCore and local LoopKit package references, plus local G7SensorKit and OmniBLE subprojects.
  • Build 843 tracks the app-workspace Package.resolved file and pins CryptoSwift exactly.
  • LoopKit also records SwiftCharts in its own package manifest and lockfile.
  • BionicLoopCore depends on two local binary artifacts (Algo2015.xcframework and Algo2015Safety.xcframework) in addition to local bridge/Swift targets.
  • The standalone LoopKit.xcodeproj development workspace lockfile records SwiftCharts revision 3d011f67eccb1ffa622fbfccb1348eed80309ae8, while the observed BionicLoop app workspace and LoopKit/Package.resolved record c354c1945bb35a1f01b665b22474f6db28cba4a2. The BionicLoop build resolves local LoopKit through the app workspace, so the standalone development workspace lockfile is not a shipped-baseline input and is excluded from the app SBOM. It must not be substituted for the shipping app resolution during freeze capture.

4.1 Exact-freeze formal-run binary checksum snapshot

These SHA-256 values were regenerated during the exact-freeze formal run. The controlled text manifest is binary-checksums.txt.

Artifact Slice SHA-256
Algo2015.xcframework/ios-arm64/libAlgo2015.a b8b6cb918882b9ae40f0dacb1e4cc235ac374f2bf3ecfbe4d6882a0903211363
Algo2015.xcframework/ios-arm64-simulator/libAlgo2015.a ef12558672946a70911279bb947d29c81f5bdb6b5822b807b0291ab1dd5de119
Algo2015.xcframework/macos-arm64_x86_64/libAlgo2015.a 97512f06d0309407884b71cf88782fb67cc790421f47771c10c708bbef3dfa2e
Algo2015Safety.xcframework/ios-arm64/libAlgo2015Safety.a 5a565f8e71ff0f9b7ffefab3ec895ec91f4e36f34a365648788e87cff5e29cac
Algo2015Safety.xcframework/ios-arm64-simulator/libAlgo2015Safety.a 6fa9470cdb05eecb6cbaadd71c5a5dbb354cb2c4a5f8c0dd953407e954337987
Algo2015Safety.xcframework/macos-arm64_x86_64/libAlgo2015Safety.a 050b7bb981241fcdde6450b996c1c172941fbee33bc8325d5d0e32d85ebfe5c6

The exact-freeze safety identity report records byte-identical primary/safety objects before the three intentional exported-symbol renames.

4.2 Exact-freeze controlled manual advisory review

  • The dated repository and GitHub global Swift advisory queries in advisory-review.md returned no published advisory requiring an immediate source change.
  • The same review records SwiftCharts' explicit unmaintained status as a maintenance residual rather than treating "no advisory" as active support.
  • gitleaks, trufflehog, syft, grype, and osv-scanner were unavailable. The controlled manual method and its limitations are accepted under D09; an approved scanner may be added later as an operational enhancement.
  • The Build 843 dependency set passed the dependency checker and its 6/6 unit tests, 8/8 OmniBLE cryptographic/session vectors, 471/471 core tests, the canonical 997-test app run with zero failures and one intentional IFU reference-table generation helper skip gated by an export directory, and 68/68 scoped security controls. Build 843 archive identity is recorded; evidence and cybersecurity acceptance are recorded under D08 and D09.

5. Current Limitations

This inventory retains these operational items:

  • required distributed acknowledgment placement
  • recurring vulnerability-monitoring ownership and cadence
  • any future decision to supplement the accepted manual method with an organization-approved scanner

6. Current Recommendation

For the current software package:

  • use this document as the current dependency-inventory floor
  • preserve exact-freeze dependency history in its execution record and retain the tracked app-workspace resolution plus fail-closed checker for Build 843 and future baselines
  • use Cybersecurity_SBOM_and_Advisory_Process.md as the current process/ownership note
  • use Cybersecurity_SBOM_Build_843.cdx.json as the machine-readable Build 843 composition record and Technical Appendix A08B as its dated license/advisory review
  • use the exact-freeze companion as the current engineering composition, checksum, identity, secret-pattern, and manual-advisory record
  • retain the recorded Build 843 archive, installation, and focused real-Pod transport evidence
  • obtain sponsor evidence disposition before final promotion and retain exact app-workspace resolution control in every future baseline