VERIFIED VERSION
OpenTelemetry eBPF Instrumentation
v0.11.0
Every version proves itself.
VersionPass issued 20 August 2026 at 06:25 UTC · Revision 1
WHY SHOULD I TRUST THIS?
Independent checks, stated precisely.
Independently verified: the VersionPass signature, canonical payload digest, exact artifact binding, and every preserved evidence digest.
Observed from an identified source: GitHub release/tag/commit metadata and OSV package-version matches.
VersionPass assessed: the Sigstore bundle matched the expected GitHub workflow identity and bound artifact when this revision was issued.
Declared by the vendor: no claims were included. Support duration has not been declared.
Could not be verified: SBOM completeness and full build provenance. Missing evidence is not silently downgraded.
RELEASE IDENTITY
The exact software evaluated
- Git tag
- v0.11.0
- Commit SHA
2f8603c7232a93e798f3673a15d8077e6a509047- Artifact
- obi-v0.11.0-linux-amd64.tar.gz
- Artifact SHA-256
5118e6e03f23…d05f0ce6- Identity strength
- Cryptographic artifact binding
CURRENTLY KNOWN
12 matched vulnerability records
Observed from OSV across 223 identified components at 20/08/2026, 06:27:56 UTC. This live observation does not mutate the signed publication snapshot.
+ 4 additional current records.
AT PUBLICATION
12 matched vulnerability records
This immutable snapshot records what the OSV query returned when revision 1 was signed.
- Source
- OSV
- Observed
- 20/08/2026, 06:25:09 UTC
- Interpretation
- Potential matches; exploitability not established
COMPONENTS / SBOM
229 components
Original SBOM preserved and digest-bound. Syntax and structure were validated; completeness was not independently assessed.
pkg:github/actions/cache@v5.0.4pkg:github/actions/checkout@v3.3.0pkg:github/actions/checkout@v6.0.2pkg:github/actions/setup-go@v3.5.0pkg:github/actions/setup-go@v6.4.0pkg:github/actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024fpkg:golang/cloud.google.com/go/compute/metadata@v0.9.0pkg:golang/github.com/AlessandroPomponio/go-gibberish@v0.0.0-20191004143433-a2d4156f0396pkg:golang/github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp@v1.35.0pkg:golang/github.com/andybalholm/brotli@v1.2.2pkg:golang/github.com/aws/aws-sdk-go-v2@v1.43.3pkg:golang/github.com/aws/aws-sdk-go-v2/config@v1.32.34Showing 12 of 229. Full inventory is included in the JSON download.
PROVENANCE
Artifact signature cryptographically verified
- Evidence
- Sigstore bundle
- OIDC issuer
- https://token.actions.githubusercontent.com
- Subject digest
- MATCHED
- Verifier
- cosign v3.1.2
- Build provenance
- UNAVAILABLE
FACTS, ASSESSMENTS & CLAIMS
Git tag v0.11.0 resolved to commit 2f8603c7232a93e798f3673a15d8077e6a509047.GitHub API
obi-v0.11.0-linux-amd64.tar.gz SHA-256 is 5118e6e03f23c153bdb69b34fbbe18000a5d63d0c29b14b3688a5263d05f0ce6.Downloaded GitHub release asset
Imported CycloneDX 1.6 SBOM contains 229 components.obi-v0.11.0-linux-amd64.cyclonedx.json
12 OSV vulnerability records matched the queried component identifiers at issue time. Match does not establish exploitability.ReleasePass
No vendor claims were included.Absence shown explicitly
CRYPTOGRAPHIC VERIFICATION
8/8 mandatory checks passed
Signature: valid · Evidence objects: all digests matched
PORTABLE VERSIONPASS
Verify and retain the evidence.
Download the signed canonical VersionPass for security review, procurement records, or independent tooling.