Still Systems, LLC — TreeResolve product site (stillsystems.github.io/treeresolve-community)
Trust Pack
Zero-cost vendor-risk materials for enterprise buyers evaluating TreeResolve. This is not a SOC 2 report and is not launch approval. Still Systems is a solo LLC; answers below are honest about that.
- Artifact: Data-flow diagram — Location: data-flow.md — Automation: Docs (synced to community)
- Artifact: SBOM (CycloneDX) — Location: GitHub Release / workflow artifact — Automation: release-artifacts.yml
- Artifact: SHA-256 + Sigstore — Location: Alongside each VSIX on release — Automation: Same workflow (keyless OIDC)
- Artifact: OpenSSF Scorecard — Location: Public community repo — Automation: Community workflow; docs sync via GitHub App PR
- Artifact: CSA CAIQ (lite) — Location: caiq-lite.md — Automation: Docs
- Artifact: VDP / security.txt — Location: SECURITY.md, security.txt — Automation: Docs + Pages
- Artifact: Offline VSIX + AllowedExtensions — Location: offline-vsix.md — Automation: Docs
Also see ENTERPRISE.md, PRIVACY.md, and ARCHITECTURE.md.
How to verify a release VSIX
# After downloading assets from the GitHub Release:
sha256sum -c treeresolve-<version>.vsix.sha256
cosign verify-blob "treeresolve-<version>.vsix" \
--bundle "treeresolve-<version>.vsix.sigstore.json" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
--certificate-identity-regexp \
'^https://github.com/stillsystems/treeresolve/\.github/workflows/release-artifacts\.yml@refs/tags/v'
SBOM file: treeresolve-<version>.cdx.json (CycloneDX JSON).