Cybersecurity Dependency Inventory¶
Status: Controlled dependency inventory accepted within the Build 843 cybersecurity scope Owner: Software Developer Last updated: 2026-09-08
1. Purpose¶
Record the current software-composition baseline visible from the checked-in BionicLoop project and local package manifests.
This inventory is a controlled dependency snapshot. The exact-freeze composition and manual-advisory companion now exists at 2026-08-21-ide-freeze-sbom-advisory-manual.
Build 843 requires CryptoSwift 1.10.0 exactly, tracks the app-workspace resolution, and uses a fail-closed checker to enforce source, version, and revision. Historical exact-freeze dependency details remain in the Freeze Execution Report and its referenced evidence; this inventory presents the current controlled build composition. The Build 843 machine-readable source is Cybersecurity_SBOM_Build_843.cdx.json, with the dated review boundary in Technical Appendix A08B.
2. Scope of This Snapshot¶
Included here:
- BionicLoop app project dependency surfaces visible in the checked-in
BionicLoop.xcodeproj - local embedded packages and subprojects shipped with the app baseline
- remote SwiftPM packages resolved for Build 843, plus their source requirements in local manifests and projects
- binary algorithm artifact referenced by the app/core baseline
Operational follow-through:
- retain required third-party acknowledgments with the distributed materials
- continue vulnerability monitoring during the study; the controlled manual
advisory method and its limitations are accepted under
D09
3. Current Dependency Snapshot¶
3.1 First-party / repo-local components in the app baseline¶
| Component | Integration Form | Current Baseline Evidence | Notes |
|---|---|---|---|
BionicLoop app target |
First-party app target | BionicLoop.xcodeproj/project.pbxproj |
Primary shipped controller application. |
BionicLoopCore |
Local Swift package | BionicLoop.xcodeproj/project.pbxproj, BionicLoopCore/Package.swift |
Local core domain/runtime package referenced through XCLocalSwiftPackageReference. |
LoopKit |
Local Swift package | BionicLoop.xcodeproj/project.pbxproj, LoopKit/Package.swift |
Local package referenced through XCLocalSwiftPackageReference. |
G7SensorKit / G7SensorKitUI |
Local embedded subproject/framework | BionicLoop.xcodeproj/project.pbxproj references G7SensorKit.xcodeproj; upstream https://github.com/LoopKit/G7SensorKit; MIT license verified from upstream LICENSE on 2026-09-03; traced sync base 624bb360c277c43daa5232df986de7467bc0b72b |
Integrated as a checked-in local Xcode subproject rather than a remote package. The monorepo does not contain the upstream license file; provenance and license identity are recorded here without asserting current-tree identity to upstream HEAD. |
OmniBLE |
Local embedded subproject/framework | BionicLoop.xcodeproj/project.pbxproj references OmniBLE.xcodeproj |
Integrated as a checked-in local Xcode subproject rather than a remote package. |
Algo2015.xcframework |
Local binary artifact | BionicLoop.xcodeproj/project.pbxproj, BionicLoopCore/Package.swift |
Binary algorithm artifact referenced from Algo2015/build/Algo2015.xcframework. |
Algo2015Bridge |
Local bridge target | BionicLoopCore/Package.swift |
Repo-local bridge between host Swift code and Algo2015 binary artifact. |
Algo2015Safety.xcframework |
Local binary artifact | BionicLoopCore binary-target declaration and the controlled safety build/identity process |
Symbol-isolated safety-controller artifact; the controlled identity report records its relationship to the primary algorithm compilation. |
Algo2015SafetyBridge |
Local bridge target | BionicLoopCore/Package.swift |
Repo-local bridge between host Swift code and the isolated safety binary. |
3.2 Remote SwiftPM dependencies observed at freeze¶
| Package | Source | Resolved Version / Revision | Evidence | Current Use Surface |
|---|---|---|---|---|
CryptoSwift |
https://github.com/krzyzanowskim/CryptoSwift |
1.10.0 / f2a627b84c1ff96f21ac2fcb623ab36142dd5512 |
Build 843 tracked resolution and dependency verification | Used by OmniBLE cryptographic/session paths; exact source, version, and revision are checked before build. |
SlideButton |
https://github.com/no-comment/SlideButton |
branch main at 5eacebba4d7deeb693592bc9a62ab2d2181e133b (1.3.0) |
Formal-run console and captured resolution | Used for slider-style controls. Branch requirement remains unpinned by the tag. |
SwiftCharts |
https://github.com/ivanschuetz/SwiftCharts |
branch master at c354c1945bb35a1f01b665b22474f6db28cba4a2 |
Formal-run console, captured resolution, LoopKit/Package.swift |
Used through LoopKitUI; upstream states the project is no longer maintained. Branch requirement remains unpinned by the tag. |
3.3 External regulatory context and non-reliance¶
The FDA 510(k) summary for Tidepool Loop, K203689, records that Tidepool
evaluated known use problems from DIY Loop, adapted its design, and performed
detailed verification and validation under the interoperable automated
glycemic-controller requirements. This provides general regulatory context for
bringing software with DIY Loop origins under formal design controls.
That clearance is not verification of BionicLoop's exact OmniBLE or
G7SensorKit source, local modifications, or Build 843 device interfaces. No
component-equivalence or inherited-verification claim is made. BionicLoop relies
on the controlled Build 843 source and its own requirements, risk management,
configuration controls, verification, and supporting real-device observations.
See the FDA Tidepool Loop 510(k) summary.
4. Current Observations¶
- The app project itself currently uses local
BionicLoopCoreand localLoopKitpackage references, plus localG7SensorKitandOmniBLEsubprojects. - Build 843 tracks the app-workspace
Package.resolvedfile and pins CryptoSwift exactly. LoopKitalso recordsSwiftChartsin its own package manifest and lockfile.BionicLoopCoredepends on two local binary artifacts (Algo2015.xcframeworkandAlgo2015Safety.xcframework) in addition to local bridge/Swift targets.- The standalone
LoopKit.xcodeprojdevelopment workspace lockfile records SwiftCharts revision3d011f67eccb1ffa622fbfccb1348eed80309ae8, while the observed BionicLoop app workspace andLoopKit/Package.resolvedrecordc354c1945bb35a1f01b665b22474f6db28cba4a2. The BionicLoop build resolves local LoopKit through the app workspace, so the standalone development workspace lockfile is not a shipped-baseline input and is excluded from the app SBOM. It must not be substituted for the shipping app resolution during freeze capture.
4.1 Exact-freeze formal-run binary checksum snapshot¶
These SHA-256 values were regenerated during the exact-freeze formal run. The controlled text manifest is binary-checksums.txt.
| Artifact Slice | SHA-256 |
|---|---|
Algo2015.xcframework/ios-arm64/libAlgo2015.a |
b8b6cb918882b9ae40f0dacb1e4cc235ac374f2bf3ecfbe4d6882a0903211363 |
Algo2015.xcframework/ios-arm64-simulator/libAlgo2015.a |
ef12558672946a70911279bb947d29c81f5bdb6b5822b807b0291ab1dd5de119 |
Algo2015.xcframework/macos-arm64_x86_64/libAlgo2015.a |
97512f06d0309407884b71cf88782fb67cc790421f47771c10c708bbef3dfa2e |
Algo2015Safety.xcframework/ios-arm64/libAlgo2015Safety.a |
5a565f8e71ff0f9b7ffefab3ec895ec91f4e36f34a365648788e87cff5e29cac |
Algo2015Safety.xcframework/ios-arm64-simulator/libAlgo2015Safety.a |
6fa9470cdb05eecb6cbaadd71c5a5dbb354cb2c4a5f8c0dd953407e954337987 |
Algo2015Safety.xcframework/macos-arm64_x86_64/libAlgo2015Safety.a |
050b7bb981241fcdde6450b996c1c172941fbee33bc8325d5d0e32d85ebfe5c6 |
The exact-freeze safety identity report records byte-identical primary/safety objects before the three intentional exported-symbol renames.
4.2 Exact-freeze controlled manual advisory review¶
- The dated repository and GitHub global Swift advisory queries in advisory-review.md returned no published advisory requiring an immediate source change.
- The same review records SwiftCharts' explicit unmaintained status as a maintenance residual rather than treating "no advisory" as active support.
gitleaks,trufflehog,syft,grype, andosv-scannerwere unavailable. The controlled manual method and its limitations are accepted underD09; an approved scanner may be added later as an operational enhancement.- The Build 843 dependency set passed the dependency
checker and its 6/6 unit tests, 8/8 OmniBLE cryptographic/session vectors,
471/471 core tests, the canonical 997-test app run with zero failures and one
intentional IFU reference-table generation helper skip gated by an export
directory, and 68/68 scoped security controls. Build 843
archive identity is recorded; evidence and cybersecurity acceptance are
recorded under
D08andD09.
5. Current Limitations¶
This inventory retains these operational items:
- required distributed acknowledgment placement
- recurring vulnerability-monitoring ownership and cadence
- any future decision to supplement the accepted manual method with an organization-approved scanner
6. Current Recommendation¶
For the current software package:
- use this document as the current dependency-inventory floor
- preserve exact-freeze dependency history in its execution record and retain the tracked app-workspace resolution plus fail-closed checker for Build 843 and future baselines
- use Cybersecurity_SBOM_and_Advisory_Process.md as the current process/ownership note
- use Cybersecurity_SBOM_Build_843.cdx.json as the machine-readable Build 843 composition record and Technical Appendix A08B as its dated license/advisory review
- use the exact-freeze companion as the current engineering composition, checksum, identity, secret-pattern, and manual-advisory record
- retain the recorded Build 843 archive, installation, and focused real-Pod transport evidence
- obtain sponsor evidence disposition before final promotion and retain exact app-workspace resolution control in every future baseline