How qtrace works
qtrace scans a repository and builds a cryptographic inventory from the information it finds.
Knowledge base
Before scanning, qtrace loads its knowledge base.
If the knowledge base cannot be parsed, the scan fails.
Repository scan
qtrace walk's through the repository in deterministic order.
Git ignore rules are respected during the scan.
For each file, qtrace determines whether it contains information relevant to cryptographic asset discovery.
Cryptographic asset discovery
qtrace checks five types of sources
These sources can provide different types of cryptographic evidence.
The result of the discovery process contains cryptographic assets and notes about anything that could not be fully identified or processed.
Building the cryptographic inventory
The discovered assets are combined into a single cryptographic bill of materials.
When the same asset is encountered more than once, qtrace keeps the occurrences and uses the highest available confidence.
Risk evaluation
After the assets are collected, qtrace evaluates them for risk.
Risk evaluation includes:
- Risk score
- Mosca verdict
- Risk classification
- Remediation
- Purpose
- Migration guidance
The risk classification includes:
| Risk class | Meaning |
|---|---|
shor-broken | Broken outright by Shor's algorithm. |
grover-weakened | Loses roughly half its security margin to Grover. |
unknown | The knowledge base has no classification. |
pqc-safe | A standardized post-quantum algorithm. |
not-applicable | Quantum risk is not the relevant question. |
Confidence
qtrace records how strongly the available evidence supports a finding.
The confidence levels are:
| Confidence | Meaning |
|---|---|
1.00 | Read directly from the artifact. |
0.90 | A resolved call site. |
0.60 | A call site whose argument did not resolve. |
0.30 | Inferred from a dependency. |
Confidence is used when ranking findings.
Notes and gaps
qtrace does not hide information that it cannot fully process.
It reports notes when something cannot be resolved, parsed, opened, classified, or supported.
The note types include:
unresolvedunparseableencryptednot-in-kbunsupported
A finding and a gap are different results.
A finding identifies a cryptographic asset.
A gap indicates that qtrace could not fully process or classify something.
Reports
After the findings have been evaluated, qtrace produces the scan output.
Supported outputs include:
- CycloneDX 1.7
- CycloneDX 1.6
- HTML
- SARIF
- Terminal summary
The HTML report contains:
- Overview
- Findings
- Files
- Migrate
- Gaps
- Provenance
Deterministic results
qtrace produces deterministic scan results.
The repository walk uses a deterministic order, the risk reference year comes from the knowledge base rather than the wall clock, and no timestamp appears in the output unless requested.
The same repository tree produces byte-identical output.