{"_id":"@confidential-ai/kettle","name":"@confidential-ai/kettle","dist-tags":{"latest":"1.1.0"},"versions":{"1.1.0":{"artifactDownloadUrls":["https://github.com/confidential-dot-ai/kettle/releases/download/v1.1.0"],"bin":{"kettle":"run-kettle.js","kettle-server":"run-kettle-server.js"},"dependencies":{"axios":"^1.13.5","axios-proxy-builder":"^0.1.2","console.table":"^0.10.0","detect-libc":"^2.1.2","rimraf":"^6.1.3"},"devDependencies":{"prettier":"^3.8.1"},"engines":{"node":">=14","npm":">=6"},"glibcMinimum":{"major":2,"series":31},"name":"@confidential-ai/kettle","preferUnplugged":true,"repository":{"type":"git","url":"git+https://github.com/confidential-dot-ai/kettle.git"},"scripts":{"fmt":"prettier --write **/*.js","fmt:check":"prettier --check **/*.js","postinstall":"node ./install.js"},"supportedPlatforms":{"x86_64-unknown-linux-gnu":{"artifactName":"kettle-x86_64-unknown-linux-gnu.tar.xz","bins":{"kettle":"kettle","kettle-server":"kettle-server"},"zipExt":".tar.xz"}},"version":"1.1.0","volta":{"node":"18.14.1","npm":"9.5.0"},"gitHead":"5bc55e5bbd7b325a82ad4bd50367b996aad13596","description":"<h1 align=\"center\">   <img src=\"docs/kettle.png\" width=\"220px\" height=\"220px\" alt=\"kettle\"> </h1>","bugs":{"url":"https://github.com/confidential-dot-ai/kettle/issues"},"homepage":"https://github.com/confidential-dot-ai/kettle#readme","_id":"@confidential-ai/kettle@1.1.0","_nodeVersion":"20.19.4","_npmVersion":"9.2.0","dist":{"integrity":"sha512-+BHE6pE++6K+mNdl0oZPiXNRWI4UvTwt4k4lyml1j1bJV2ZyuLKCM5uXyC++uTDrJMp9uxaPlckexk1tbnwF1Q==","shasum":"fdf8f7fd5f062b9b20e43339261511a214090b12","tarball":"https://registry.npmjs.org/@confidential-ai/kettle/-/kettle-1.1.0.tgz","fileCount":9,"unpackedSize":39827,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCXbjgNom0LytcCS/+xp4PktWFYrNOi93sR2NWZGMah6AIhAOhdrAls0H+96he7Yws5gPDqD5Z5v9pKNxYul1SeVtKs"}]},"_npmUser":{"name":"indirect","email":"andre@arko.net"},"directories":{},"maintainers":[{"name":"indirect","email":"andre@arko.net"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/kettle_1.1.0_1782430530914_0.5335093322290703"},"_hasShrinkwrap":true}},"time":{"created":"2026-06-25T23:35:30.725Z","1.1.0":"2026-06-25T23:35:31.128Z","modified":"2026-06-25T23:35:31.359Z"},"maintainers":[{"name":"indirect","email":"andre@arko.net"}],"description":"<h1 align=\"center\">   <img src=\"docs/kettle.png\" width=\"220px\" height=\"220px\" alt=\"kettle\"> </h1>","homepage":"https://github.com/confidential-dot-ai/kettle#readme","repository":{"type":"git","url":"git+https://github.com/confidential-dot-ai/kettle.git"},"bugs":{"url":"https://github.com/confidential-dot-ai/kettle/issues"},"readme":"<h1 align=\"center\">\n  <img src=\"docs/kettle.png\" width=\"220px\" height=\"220px\" alt=\"kettle\">\n</h1>\n\n# Kettle, for attested builds\n\nKettle builds and verifies **attested builds**, packages that include cryptographically signed SLSA provenance certifying the source, tools, and machine used to create the build.\n\n**Get just the good parts of reproducible builds: the security and assurance of signed and provable inputs, without the misery of constantly repairing your build system.**\n\n## Why attested builds?\n\nAttested builds allow anyone to verify the exact inputs that produced any binary output, by adding cryptographic signatures showing exactly what source code, dependencies, and toolchains were used.\n\nKettle uses TEEs (Trusted Execution Environments) to sign builds using hardware attestation. Hardware attestations are verified against certificates published by the hardware manufacturer, cryptographically linking binaries to their exact source code.\n\n### Use cases for attested builds\n\nKettle's attested builds provide a solution to almost every scenario where binaries need a verification trail directly back to the source code and tools that created them. This is just a few examples of problems Kettle can solve:\n\n- A customer deploying your service wants to know it’s running the code you claim, built from the source they audited.\n- A compliance team wants evidence that a binary was built with specific dependency versions, not newer ones with unknown changes.\n- A security auditor wants to verify that the toolchain used to compile a release matches the one specified in your security documentation.\n- A regulated enterprise wants proof that sensitive data will be processed only by code that passed their review, not by a modified version.\n- A package consumer wants to ensure that the binary they downloaded corresponds to the source code and dependencies they reviewed, not a tampered version.\n\nFor a full tour of Kettle's design, architecture, and security guarantees, read our guide to attested builds.\n\n1. [What are Attested Builds?](/docs/1-attested-builds.md)\n2. [How Attested Builds Work](/docs/2-how-it-works.md)\n3. [Provenance and Standards](/docs/3-provenance-standards.md)\n4. [Threat Model and Security Boundaries](/docs/4-threat-model.md)\n\n## Why attest with Kettle?\n\nMost build systems can't provide hardware-secured build machines. Kettle ensures your build was created and signed inside a confidential virtual machine, with memory and compute secured even against a malicious hypervisor. In contrast, if you use GitHub's [artifact attestations](https://docs.github.com/en/actions/concepts/security/artifact-attestations), you are forced to simply take GitHub's word that their cloud VMs didn't tamper with your build.\n\nUsing Kettle to build and attest inside a TEE gives you hardware-based cryptographic assertion, dramatically reducing the number of parties you are forced to trust. You only need to trust the hardware manufacturer and the physical custodians of your build machines. No need to trust the sysadmins with root on the bare metal, or the authors of the hypervisor that creates and manages your build VMs, or the developers maintaining the image your code will run on. The code that runs in your TEE is signed by the hardware, so you can be sure what ran, and encrypted so even the hypervisor can't read the memory of your job as it runs.\n\n## Installing Kettle\n\nKettle is available from GitHub Releases or from source via Cargo, the Rust build tool.\n\n### From GitHub Releases\n\n```bash\ncurl -LO https://github.com/confidential-dot-ai/kettle/releases/latest/download/kettle-installer.sh\n# don't forget to read the source before you run random scripts from the internet :)\nbash kettle-installer.sh\n```\n\n### From source\n\nTo install Kettle, first [install Rust](https://rustup.rs), and then use Cargo to build and install:\n\n```bash\ncargo install --git https://github.com/confidential-dot-ai/kettle\n```\n\nIf you are running inside a TEE, you will need to install OS packages for attestation, and then enable the `attest` feature flag. Here's an example for Ubuntu Linux:\n\n```bash\napt-get install -y libtss2-dev\ncargo install --features attest --git https://github.com/confidential-dot-ai/kettle\n```\n\n### Reproducible build\n\nEvery release of Kettle includes a full reproducible binary, with support for attestation, built inside a fully reproducible environment in Docker. Download and use the fully reproducible binary by running:\n\n```bash\ncurl -LO https://github.com/confidential-dot-ai/kettle/releases/latest/download/kettle-reproducible-x86_64-unknown-linux-gnu.tar.xz\ntar xfvj kettle-reproducible-x86_64-unknown-linux-gnu.tar.xz \nchmod +x kettle\n./kettle attest\n```\n\n## Using Kettle\n\n### Build anywhere\n\nRun `kettle build` to do all the steps except the hardware cryptography: generate a SLSA-compliant `provenance.json` file, build the project, and checksum the binaries. Use this command to test your build process even if you aren't inside a TEE.\n\n![`kettle build` will generate the provenance, build the project, and checksum the binaries](/docs/build.png)\n\nToday, Kettle supports building and attesting Rust and Nix projects. It's easy to add additional toolchains, and we plan to add first-party support for Python and Go soon.\n\nThis example will check out the `ripgrep` search tool, build a binary, and generate a provenance file:\n\n```bash\ngit clone https://github.com/burntsushi/ripgrep\nkettle build ripgrep\n```\n\nAfter Kettle finishes running, look for the provenance and binaries are available inside the `kettle-build` directory.\n\n### Attest from a TEE\n\nRun `kettle attest` to run a build, record the VM firmware and OS image, then apply a hardware signature to everything to create an `evidence.json` file.\n\n![`kettle attest` will build if needed, then create hardware-signed evidence containing the checksum of the provenance file and confidential VM launch mearusements](/docs/attest.png)\n\nWhile running inside a TEE, this will check out, build, and attest the `ripgrep` search tool:\n\n```bash\ngit clone https://github.com/burntsushi/ripgrep\nkettle attest ripgrep\n```\n\nAfter Kettle finishes running, the provenance, attestation, and binaries are available inside the `kettle-build` directory.\n\n### Verify anywhere\n\nRun `kettle verify` to cryptographically verify your binaries. Kettle will read the `evidence.json`, verify the signature using hardware vendor public keys, and then validate the signed `provenance.json` and use it to confirm the checksum of your binary.\n\n![verify the hardware-signed evidence, which provides the checksums for the provenance and binary, which you can use to prove which source code, dependencies, and toolchain were used](/docs/verify.png)\n\nVerify the attested build created above like this:\n\n```bash\nkettle verify ripgrep/kettle-build\n```\n\nTwo optional flags tie the attestation to the exact VM image that produced it:\n\n- `--igvm <FILE>` — verify that the attested launch measurement matches this IGVM\n  file's launch digest, proving the build ran in a confidential VM booted from\n  exactly this IGVM.\n- `--image <FILE>` — verify that the dm-verity roothash committed inside the IGVM\n  matches the roothash stored in this disk image (`disk.raw`), binding the\n  verified IGVM to a specific root filesystem. Requires `--igvm`.\n\n```bash\nkettle verify ripgrep/kettle-build --igvm guest.igvm --image disk.raw\n```\n\n## Supported toolchains\n\nToday, Kettle supports building, attesting, and verifying software packaged with:\n\n- Cargo, for programs written in Rust\n- pnpm, for programs written in JavaScript and TypeScript\n- nix, for programs written in any language\n\nPlanned toolchain support includes:\n\n- uv, for programs written in Python\n- go, for programs written in Go\n\n## Development\n\nUse `cargo nextest run` to run the tests for any platform.\n\nIn a TEE, use `cargo nextest run --ignored all` to run the full integration tests that checkout Rust and Nix projects, build them, attest them, and verify them.\n\nRun `bin/build-reproducible` to use Docker images provided by the StageX project to build a byte-for-byte reproducible build of Kettle into `./target/reproducible/kettle`.\n","readmeFilename":"README.md","_rev":"1-01eac2b29cd2f60902e32316d8beae48"}