What is qtrace?
qtrace is a cryptographic bill of materials scanner for repositories.
It scans the code where it already lives and identifies cryptographic assets across the repository. It then classifies those assets according to their quantum vulnerability and provides information about where they were found.
What qtrace provides
qtrace provides:
- Cryptographic asset discovery
- Quantum risk classification
- File and line information
- Confidence information
- Risk scoring
- Remediation guidance
- Migration guidance
- Reports in multiple formats
- Gaps where an asset could not be read or classified
How qtrace works
When you run a scan, qtrace examines the repository and collects cryptographic information from:
- Manifest and lock files
- Cryptographic artifacts
- Configuration
- Source code
- Binaries
The detected information is combined into scan findings and evaluated for risk.
Quantum risk classification
qtrace classifies cryptographic assets using risk classes including:
shor-brokengrover-weakenedunknownpqc-safenot-applicable
The risk classification is used together with confidence information to rank findings.
Findings
A finding identifies a cryptographic asset and provides information such as:
- Algorithm
- File
- Line
- Risk classification
- Confidence
- Recommended action
qtrace reports gaps when it cannot read or classify something. A repository with no findings is different from a repository where something could not be read or classified.
Remediation and migration
qtrace separates remediation from migration.
Remediation explains what is wrong with the detected algorithm and identifies the recommended destination.
Migration provides guidance based on what qtrace actually found, such as the library or source call site involved.
Migration recommendations can be either:
- Product - a quant0 offering
- Advisory - an action to perform yourself
Deterministic results
The same repository tree produces the same output.
qtrace uses deterministic ordering, and the risk reference year comes from the knowledge base rather than the wall clock.
Re-running a scan against the same tree produces byte-identical output.
Scan outputs
qtrace can produce:
- HTML reports
- CycloneDX 1.7
- CycloneDX 1.6
- SARIF
- Terminal summaries
The HTML report includes:
- Overview
- Findings
- Files
- Migrate
- Gaps
- Provenance