# Pinned pyca/cryptography inventory demonstration

Prepared 10 October 2026. Repeatable with access to Cryptagion's private scanner repository. Public target source and inspectable outputs do not imply unrestricted scanner availability. No pyca endorsement is implied.

## Inputs and prerequisites

- Target repository: https://github.com/pyca/cryptography
- Target commit: `d45b7930f93c9f139ab09cfb91990e3250bc989b`
- Scanner repository: https://github.com/Cryptagion-io/cryptagion (private; authenticated access required)
- Scanner commit: `4c9ee2e47abd6892776745bd43b9597d891e5c22`, package version 0.0.1
- Observed runtime: Python 3.12.14 on macOS; locked scanner environment built with uv. No scanner source changes.
- Demonstration runs normal Evaluation mode with an isolated database and no licence file. Existing production databases are not touched. A separate installation may require a valid entitlement depending on its version and packaging.
- Scope: Python AST scan, tests and documentation scripts included, vendor excluded. No target code execution, target package installation, certificate scan, TLS connections, or cloud credentials.
- Policy: public / 0 confidentiality years. This models public repository material, not the data handled by dependent applications.

The scripts remove common AI service keys from the scanner child environment. The command uses the local AST analyzer and offline narrative is not requested. We did not independently instrument network egress or certify air-gap operation.

## Obtain exact inputs

Use separate scanner and target directories. Commands below assume `/tmp/cryptagion-scanner`, `/tmp/pyca-cryptography`, and an extracted evidence bundle in the current directory. Change those arguments for your environment.

```sh
git clone https://github.com/Cryptagion-io/cryptagion.git /tmp/cryptagion-scanner
git -C /tmp/cryptagion-scanner checkout --detach 4c9ee2e47abd6892776745bd43b9597d891e5c22
git clone https://github.com/pyca/cryptography.git /tmp/pyca-cryptography
git -C /tmp/pyca-cryptography checkout --detach d45b7930f93c9f139ab09cfb91990e3250bc989b
uv sync --project /tmp/cryptagion-scanner --frozen --no-default-groups --extra dev --python 3.12
```

Do not run builds or tests in the target repository for this demonstration. Source is read as data. The runner requires unchanged tracked files at the exact pinned commits and a fresh output directory for each run. Its input manifest hashes all tracked regular files; source symlink behavior is governed by the scanner's root check.

## Validate the supplied records

From the extracted bundle directory, with the pinned target available:

```sh
/tmp/cryptagion-scanner/.venv/bin/python validate_pyca.py --target /tmp/pyca-cryptography
```

The bundled schemas were obtained from the official CycloneDX specification v1.6: `https://github.com/CycloneDX/specification/tree/1.6/schema`.

## Repeat into fresh directories

```sh
/tmp/cryptagion-scanner/.venv/bin/python reproduce_pyca.py --scanner /tmp/cryptagion-scanner --target /tmp/pyca-cryptography --output /tmp/pyca-rerun/run-1
/tmp/cryptagion-scanner/.venv/bin/python reproduce_pyca.py --scanner /tmp/cryptagion-scanner --target /tmp/pyca-cryptography --output /tmp/pyca-rerun/run-2
/tmp/cryptagion-scanner/.venv/bin/python validate_pyca.py --target /tmp/pyca-cryptography --runs-root /tmp/pyca-rerun
```

Each run writes scan JSON, automated risk JSON, a raw CycloneDX 1.6 CBOM, policy, command logs, an inventory database, and a manifest. The supplied evidence bundle includes both isolated SQLite inventories. These contain public-source detections and are separate from any production database. All recorded output hashes are checked.

The validator compares findings after removing generated IDs and detection timestamps, and compares associated scores after replacing asset IDs with the corresponding normalized finding and removing assessment timestamps. It also verifies schema validity, ID joins, source path/line existence, requested Python scope counts, target commit, and distributed output hashes. It does not prove algorithm-label accuracy, detection recall, or deployment risk.

## Observed results and limitations

Both original runs scanned 243 Python files with zero reported skips/failures and returned 1,804 detections (46 library, 1,746 tests, 12 documentation scripts). All CBOM components and score records joined to findings. Source occurrences existed in the pinned target. The CBOM passed the official schema. Normalized findings and scores matched across the two runs on the same machine.

109 Rust files, 33 Python stub files, other languages, embedded CFFI definitions, external dependencies, live endpoints, and runtime behavior are outside the asserted coverage. In particular, the Fernet Python wrapper delegates to Rust. A lack of Python detections does not establish an absence of cryptography.

Manual review covers all 46 library-source detections, recorded in `library-review.csv`. Categories are 14 hash lookup entries, 14 context-dependent uses, 10 imports/references, 7 curve references, and 1 generic CBC capability check whose AES family is not established. A DSA test call at `tests/hazmat/primitives/test_dsa.py:113` is mislabeled Diffie–Hellman in the raw scan. The complete test set has not received a ground-truth accuracy assessment.

The raw risk output uses heuristic scores. It does not establish vulnerabilities, business impact, migration budgets, replacement suitability, or a remediation deadline. MD5/SHA-1 share the vulnerable enum with quantum-related algorithms; do not report a quantum exposure percentage from that field. The raw CBOM has no complete dependency graph.
