Security model

Package policy, vulnerability and secret scanning, SBOM export, Sigstore checks, telemetry, and the tamper-evident audit log.

Security grades

How OMG classifies packages

GradeClassification
LockedReserved for provenance evidence. Automatic grading does not assign it
VerifiedOfficial repository metadata identifies the package
CommunityAUR and other nonofficial package sources
RiskThe configured vulnerability scanner found a known vulnerability

Vulnerability scanning

In the published v0.1.223 release, omg audit scan requires a running omgd. It queries OSV.dev for installed packages. The release maps macOS packages to the Homebrew ecosystem, although effective finding coverage has not been verified; Fedora has no OSV mapping. Current main can scan without a daemon and uses Arch Linux advisories on Arch, native DNF advisories on Fedora, and OSV on Debian and Ubuntu. A scan that finds no advisories is not proof that every package is safe. Finding vulnerabilities is reported but does not, by itself, make the command fail.

Scan and report

omg audit
omg audit scan
omg audit log --severity error
omg audit eol

Artifact signature verification

How an artifact signature is checked A successful check ties the file you hold to the signing identity you specified. It is not a build-level or safety verdict.
How an artifact signature is checkedHow an artifact signature is checked. Steps in reading order: Downloaded artifact (the file you hold); Expected identity (email or OIDC URI); SHA-256 digest (computed locally); Rekor SET (signed entry timestamp); Fulcio certificate (chain checked); Signature verified (identity is bound); Not a SLSA level (nor proof of safety). Connections: Downloaded artifact to SHA-256 digest; SHA-256 digest to Rekor SET; Rekor SET to Fulcio certificate; Fulcio certificate to Signature verified; Expected identity to Signature verified (must match); Signature verified to Not a SLSA level (with limits).Downloaded artifactthe file you holdExpected identityemail or OIDC URISHA-256 digestcomputed locallyRekor SETsigned entry timestampFulcio certificatechain checkedSignature verifiedidentity is boundNot a SLSA levelnor proof of safetymust matchwith limits
  • Runtime installers and self-update compare downloaded bytes with the expected SHA-256 digest when that digest is available.
  • AUR key preparation invokes gpg to inspect and import keys required by a build.
  • omg audit slsa verifies a Sigstore hashedrekord artifact signature and Rekor signed entry timestamp (SET) against the pinned log key. It does not independently verify a Merkle inclusion proof or checkpoint.
  • Supply an expected publisher email or OIDC URI with `--certificate-identity`. In v0.1.223, the parser accepts omission but the verifier rejects it; the newer CLI checkout requires the option at parsing.
  • The current hashedrekord check does not establish build provenance or assign a SLSA level. It is a standalone audit and does not gate installation.

Verify a downloaded artifact

omg audit slsa artifacts/package.pkg.tar.zst --certificate-identity "$EXPECTED_SIGNER_IDENTITY"

Policy enforcement

On Arch, OMG checks policy.toml against the prepared ALPM transaction, including dependencies. It rejects candidates below minimum_grade, disallowed AUR sources, packages below Verified when require_pgp is true, licenses outside allowed_licenses, and banned_packages. Native APT, DNF, and Homebrew installs and upgrades refuse an explicit policy because a separate precheck cannot guarantee their final transactions.

Inspect the active policy

omg audit policy

SBOM generation and compliance

Generate and export evidence

omg audit sbom -o sbom.json
omg audit log --export audit.csv
omg audit export --framework soc2 --output ./audit-evidence
omg enterprise audit-export --framework soc2 --period 2026-Q1

In v0.1.223, the CLI writes a CycloneDX 1.5 system-package SBOM on Arch. Debian and Ubuntu have an inventory path, but required vulnerability matching fails there in that release. Current main supports Arch, Debian, Ubuntu, and Fedora when inventory and advisory data are available; Homebrew is unsupported. The SBOM contains installed package identities and matched findings, not application dependency graphs. An inventory or advisory failure stops generation.

License review and vulnerability fixes

Review installed package licenses on Arch

omg audit licenses
omg audit licenses --check-policy
omg audit fix --dry-run

The installed-package license report and automatic vulnerability fix currently require the Arch backend. On Debian, Ubuntu, Fedora, and macOS they return an unsupported-backend error rather than a clean bill of health. In v0.1.223, --check-policy prints violations but does not fail solely because it found them; --filter also narrows the packages it checks. Inspect the complete report before treating it as a policy gate. omg audit fix upgrades affected Arch packages only when updates are available; review the dry run first.

Secret scanning

Detected credential families

Credential typeSeverity
AWS access and secret keysCritical
GitHub and GitLab tokensCritical
Private keysCritical
Stripe live keysCritical
Slack tokens and Google API keysHigh
NPM tokensHigh
JWT and generic API keys or passwordsMedium

Scan a project

omg audit secrets
omg audit secrets -p /path/to/project

Tamper-evident audit log

Package changes, security scan summaries, policy rejections, and daemon lifecycle events are appended to audit/audit.jsonl under the OMG data directory. Editing a retained entry breaks its hash chain. The local chain cannot prove that an attacker with filesystem access did not delete or truncate entries.

Review and prove integrity

omg audit log --limit 50
omg audit verify

How each entry is linked

# entry N carries both the previous entry hash and its own:
#   "prev_hash": hash(entry N-1)
#   "hash":      sha256(canonical fields + prev_hash)

# Writers read the last hash under a lock, so two concurrent processes
# cannot fork the chain, and a writer that starts after another one has
# appended keeps the linkage correct instead of reusing a stale value.

# verify recomputes the linkage and reports the first entry that does not match
omg audit verify

Telemetry is opt-in

  • Runtime telemetry is disabled by default and activates only after you explicitly enable it.
  • Installer tracking asks for consent, defaults to no, and can be skipped permanently with OMG_NO_TELEMETRY=1.
  • At runtime, OMG_TELEMETRY=0 or OMG_DISABLE_TELEMETRY=1 also disables collection.
  • Collected telemetry never includes package names, search queries, file paths, arguments, or error output.
  • Events are queued locally in your data directory and sent only over HTTPS, and network failures never fail the command you ran.

Manage telemetry and export local data

omg privacy status
omg privacy opt-out
omg privacy export

Reviewed against omg-cli/omg/docs/security.md at commit c43c8ff on 2026-09-22. This page was checked against the CLI code and documentation at that commit.