Security model
Package policy, vulnerability and secret scanning, SBOM export, Sigstore checks, telemetry, and the tamper-evident audit log.
Security grades
How OMG classifies packages
| Grade | Classification |
|---|---|
| Locked | Reserved for provenance evidence. Automatic grading does not assign it |
| Verified | Official repository metadata identifies the package |
| Community | AUR and other nonofficial package sources |
| Risk | The configured vulnerability scanner found a known vulnerability |
Vulnerability scanning
In the published v0.1.223 release, omg audit scan requires a running omgd. It queries OSV.dev for installed packages. The release maps macOS packages to the Homebrew ecosystem, although effective finding coverage has not been verified; Fedora has no OSV mapping. Current main can scan without a daemon and uses Arch Linux advisories on Arch, native DNF advisories on Fedora, and OSV on Debian and Ubuntu. A scan that finds no advisories is not proof that every package is safe. Finding vulnerabilities is reported but does not, by itself, make the command fail.
Scan and report
omg audit
omg audit scan
omg audit log --severity error
omg audit eolArtifact signature verification
- Runtime installers and self-update compare downloaded bytes with the expected SHA-256 digest when that digest is available.
- AUR key preparation invokes gpg to inspect and import keys required by a build.
- omg audit slsa verifies a Sigstore hashedrekord artifact signature and Rekor signed entry timestamp (SET) against the pinned log key. It does not independently verify a Merkle inclusion proof or checkpoint.
- Supply an expected publisher email or OIDC URI with `--certificate-identity`. In v0.1.223, the parser accepts omission but the verifier rejects it; the newer CLI checkout requires the option at parsing.
- The current hashedrekord check does not establish build provenance or assign a SLSA level. It is a standalone audit and does not gate installation.
Verify a downloaded artifact
omg audit slsa artifacts/package.pkg.tar.zst --certificate-identity "$EXPECTED_SIGNER_IDENTITY"Policy enforcement
On Arch, OMG checks policy.toml against the prepared ALPM transaction, including dependencies. It rejects candidates below minimum_grade, disallowed AUR sources, packages below Verified when require_pgp is true, licenses outside allowed_licenses, and banned_packages. Native APT, DNF, and Homebrew installs and upgrades refuse an explicit policy because a separate precheck cannot guarantee their final transactions.
Inspect the active policy
omg audit policySBOM generation and compliance
Generate and export evidence
omg audit sbom -o sbom.json
omg audit log --export audit.csv
omg audit export --framework soc2 --output ./audit-evidence
omg enterprise audit-export --framework soc2 --period 2026-Q1In v0.1.223, the CLI writes a CycloneDX 1.5 system-package SBOM on Arch. Debian and Ubuntu have an inventory path, but required vulnerability matching fails there in that release. Current main supports Arch, Debian, Ubuntu, and Fedora when inventory and advisory data are available; Homebrew is unsupported. The SBOM contains installed package identities and matched findings, not application dependency graphs. An inventory or advisory failure stops generation.
License review and vulnerability fixes
Review installed package licenses on Arch
omg audit licenses
omg audit licenses --check-policy
omg audit fix --dry-runThe installed-package license report and automatic vulnerability fix currently require the Arch backend. On Debian, Ubuntu, Fedora, and macOS they return an unsupported-backend error rather than a clean bill of health. In v0.1.223, --check-policy prints violations but does not fail solely because it found them; --filter also narrows the packages it checks. Inspect the complete report before treating it as a policy gate. omg audit fix upgrades affected Arch packages only when updates are available; review the dry run first.
Secret scanning
Detected credential families
| Credential type | Severity |
|---|---|
| AWS access and secret keys | Critical |
| GitHub and GitLab tokens | Critical |
| Private keys | Critical |
| Stripe live keys | Critical |
| Slack tokens and Google API keys | High |
| NPM tokens | High |
| JWT and generic API keys or passwords | Medium |
Scan a project
omg audit secrets
omg audit secrets -p /path/to/projectTamper-evident audit log
Package changes, security scan summaries, policy rejections, and daemon lifecycle events are appended to audit/audit.jsonl under the OMG data directory. Editing a retained entry breaks its hash chain. The local chain cannot prove that an attacker with filesystem access did not delete or truncate entries.
Review and prove integrity
omg audit log --limit 50
omg audit verifyHow each entry is linked
# entry N carries both the previous entry hash and its own:
# "prev_hash": hash(entry N-1)
# "hash": sha256(canonical fields + prev_hash)
# Writers read the last hash under a lock, so two concurrent processes
# cannot fork the chain, and a writer that starts after another one has
# appended keeps the linkage correct instead of reusing a stale value.
# verify recomputes the linkage and reports the first entry that does not match
omg audit verifyTelemetry is opt-in
- Runtime telemetry is disabled by default and activates only after you explicitly enable it.
- Installer tracking asks for consent, defaults to no, and can be skipped permanently with OMG_NO_TELEMETRY=1.
- At runtime, OMG_TELEMETRY=0 or OMG_DISABLE_TELEMETRY=1 also disables collection.
- Collected telemetry never includes package names, search queries, file paths, arguments, or error output.
- Events are queued locally in your data directory and sent only over HTTPS, and network failures never fail the command you ran.
Manage telemetry and export local data
omg privacy status
omg privacy opt-out
omg privacy export