Skip to main content

How qtrace works

qtrace scans a repository and builds a cryptographic inventory from the information it finds.

Knowledge base​

Before scanning, qtrace loads its knowledge base.

If the knowledge base cannot be parsed, the scan fails.

Repository scan​

qtrace walk's through the repository in deterministic order.

Git ignore rules are respected during the scan.

For each file, qtrace determines whether it contains information relevant to cryptographic asset discovery.

Cryptographic asset discovery​

qtrace checks five types of sources

These sources can provide different types of cryptographic evidence.

The result of the discovery process contains cryptographic assets and notes about anything that could not be fully identified or processed.

Building the cryptographic inventory​

The discovered assets are combined into a single cryptographic bill of materials.

When the same asset is encountered more than once, qtrace keeps the occurrences and uses the highest available confidence.

Risk evaluation​

After the assets are collected, qtrace evaluates them for risk.

Risk evaluation includes:

  • Risk score
  • Mosca verdict
  • Risk classification
  • Remediation
  • Purpose
  • Migration guidance

The risk classification includes:

Risk classMeaning
shor-brokenBroken outright by Shor's algorithm.
grover-weakenedLoses roughly half its security margin to Grover.
unknownThe knowledge base has no classification.
pqc-safeA standardized post-quantum algorithm.
not-applicableQuantum risk is not the relevant question.

Confidence​

qtrace records how strongly the available evidence supports a finding.

The confidence levels are:

ConfidenceMeaning
1.00Read directly from the artifact.
0.90A resolved call site.
0.60A call site whose argument did not resolve.
0.30Inferred from a dependency.

Confidence is used when ranking findings.

Notes and gaps​

qtrace does not hide information that it cannot fully process.

It reports notes when something cannot be resolved, parsed, opened, classified, or supported.

The note types include:

  • unresolved
  • unparseable
  • encrypted
  • not-in-kb
  • unsupported

A finding and a gap are different results.

A finding identifies a cryptographic asset.

A gap indicates that qtrace could not fully process or classify something.

Reports​

After the findings have been evaluated, qtrace produces the scan output.

Supported outputs include:

  • CycloneDX 1.7
  • CycloneDX 1.6
  • HTML
  • SARIF
  • Terminal summary

The HTML report contains:

  • Overview
  • Findings
  • Files
  • Migrate
  • Gaps
  • Provenance

Deterministic results​

qtrace produces deterministic scan results.

The repository walk uses a deterministic order, the risk reference year comes from the knowledge base rather than the wall clock, and no timestamp appears in the output unless requested.

The same repository tree produces byte-identical output.