Build 843 SBOM and Advisory Review¶
| Field | Value |
|---|---|
| Build | BionicLoop 1.0 (843), source 1455cda7ad5d3e164b4a955ea0e3bc725a9996e9 |
| Archive SHA-256 | 80449b03c92dbc6aa21b5f255722522757f767ee84d303ab3af2b3b86f836ac0 |
| Machine-readable SBOM | Cybersecurity_SBOM_Build_843.cdx.json, CycloneDX 1.5 |
| Review date | 2026-09-03 |
| Method | Controlled manifest comparison, local license inspection, and dated GitHub repository/advisory review |
| Status | Engineering review and listed limitations accepted within D09; operational follow-up retained |
Composition Result¶
The machine-readable SBOM records the Build 843 application, repository-local
packages, both Algo2015 binaries, and all three Swift Package Manager
dependencies. The external pins exactly match the controlled
Package.resolved file:
| Component | Build 843 identity | License review |
|---|---|---|
| CryptoSwift | 1.10.0 / f2a627b84c1ff96f21ac2fcb623ab36142dd5512 |
Project attribution license; required acknowledgment must be retained |
| SlideButton | 5eacebba4d7deeb693592bc9a62ab2d2181e133b |
MIT |
| SwiftCharts | c354c1945bb35a1f01b665b22474f6db28cba4a2 |
Apache-2.0 |
| LoopKit | repository-local Build 843 source | MIT |
| OmniBLE | repository-local Build 843 source | MIT |
| G7SensorKit | repository-local Build 843 source; traced upstream sync base 624bb360c277c43daa5232df986de7467bc0b72b from https://github.com/LoopKit/G7SensorKit |
MIT license verified from the upstream LICENSE file on 2026-09-03; the monorepo does not contain a local license copy |
| Algo2015 / Algo2015Safety | sponsor source b855f871c80e95d6f9226f54b0e60168ff603e36 |
Separately controlled sponsor source; external open-source license not asserted |
Dated Advisory Review¶
On 2026-08-27, GitHub's Swift Advisory Database was queried for CryptoSwift
1.10.0, SlideButton, and SwiftCharts at their controlled identities. No matching
advisories were returned. CryptoSwift 1.10.0 was also confirmed as the upstream
release associated with commit f2a627b.
This is a dated public-database review, not output from an organization-approved software-composition scanner. It does not establish that no vulnerability exists. Repository-local forks, proprietary device behavior, iOS, and the separately controlled algorithm require their own monitoring and supplier evidence boundary.
Operational Follow-Up¶
- retain the accepted controlled manual method and consider an approved scanner as a future operational enhancement
- retain the recorded G7SensorKit upstream/license attribution and decide the distributed acknowledgment placement
- retain the CryptoSwift acknowledgment in distributed documentation
- establish the owner and cadence for vulnerability monitoring during the investigation
- assess whether newly identified vulnerabilities require a software change, labeling/consent update, IDE report, or emergency action
The IDE Cybersecurity Closure Matrix tracks these actions without presenting the Build 843 dependency verification as broader cybersecurity closure.