Skip to content

Build 843 SBOM and Advisory Review

Field Value
Build BionicLoop 1.0 (843), source 1455cda7ad5d3e164b4a955ea0e3bc725a9996e9
Archive SHA-256 80449b03c92dbc6aa21b5f255722522757f767ee84d303ab3af2b3b86f836ac0
Machine-readable SBOM Cybersecurity_SBOM_Build_843.cdx.json, CycloneDX 1.5
Review date 2026-09-03
Method Controlled manifest comparison, local license inspection, and dated GitHub repository/advisory review
Status Engineering review and listed limitations accepted within D09; operational follow-up retained

Composition Result

The machine-readable SBOM records the Build 843 application, repository-local packages, both Algo2015 binaries, and all three Swift Package Manager dependencies. The external pins exactly match the controlled Package.resolved file:

Component Build 843 identity License review
CryptoSwift 1.10.0 / f2a627b84c1ff96f21ac2fcb623ab36142dd5512 Project attribution license; required acknowledgment must be retained
SlideButton 5eacebba4d7deeb693592bc9a62ab2d2181e133b MIT
SwiftCharts c354c1945bb35a1f01b665b22474f6db28cba4a2 Apache-2.0
LoopKit repository-local Build 843 source MIT
OmniBLE repository-local Build 843 source MIT
G7SensorKit repository-local Build 843 source; traced upstream sync base 624bb360c277c43daa5232df986de7467bc0b72b from https://github.com/LoopKit/G7SensorKit MIT license verified from the upstream LICENSE file on 2026-09-03; the monorepo does not contain a local license copy
Algo2015 / Algo2015Safety sponsor source b855f871c80e95d6f9226f54b0e60168ff603e36 Separately controlled sponsor source; external open-source license not asserted

Dated Advisory Review

On 2026-08-27, GitHub's Swift Advisory Database was queried for CryptoSwift 1.10.0, SlideButton, and SwiftCharts at their controlled identities. No matching advisories were returned. CryptoSwift 1.10.0 was also confirmed as the upstream release associated with commit f2a627b.

This is a dated public-database review, not output from an organization-approved software-composition scanner. It does not establish that no vulnerability exists. Repository-local forks, proprietary device behavior, iOS, and the separately controlled algorithm require their own monitoring and supplier evidence boundary.

Operational Follow-Up

  • retain the accepted controlled manual method and consider an approved scanner as a future operational enhancement
  • retain the recorded G7SensorKit upstream/license attribution and decide the distributed acknowledgment placement
  • retain the CryptoSwift acknowledgment in distributed documentation
  • establish the owner and cadence for vulnerability monitoring during the investigation
  • assess whether newly identified vulnerabilities require a software change, labeling/consent update, IDE report, or emergency action

The IDE Cybersecurity Closure Matrix tracks these actions without presenting the Build 843 dependency verification as broader cybersecurity closure.