LLM MeasurementGitHub
Guides

For security reviewers

Review what each tool reads, where it runs, and how to verify the exact release before using your data.

Data paths

The read-only LiteLLM SQL projection selects request metadata and usage fields, excluding prompts and responses. The request-level export still contains raw identity columns; keep it private and give the export role SELECT access only. The export recipe writes to a restricted local directory.

Identity handling

Canonicalized identities are keyed with HMAC-SHA256 before entering sketches. Supported user, session and prompt values appear as keyed hashes in summaries and as aliases in fleetdiff's default reports, rather than raw IDs. These identifiers are pseudonymous: protect the key and access to linkable outputs. Use compatible identity fields, domains and keys when combining summaries. See the hashing contract and report-sharing guidance.

The collector's original trace stream and local captures retain their source data. Configure content capture and backend access separately; hashing the selected ranking fields does not redact the original spans. Summary metadata such as producer and scope names is cleartext.

Verify fleetdiff without piping a script to a shell

Use trusted installations of curl, GitHub CLI (gh), shasum and tar. These commands download files into a new directory, verify build provenance for the archive, checksum manifest and SPDX SBOM, check the archive's checksum, then extract. Choose your platform using the two variables below. The release has Linux and macOS archives for amd64 and arm64.

set -eu
umask 077
review=$(mktemp -d ./fleetdiff-review.XXXXXX)
cd "$review"
os=$(uname -s | tr '[:upper:]' '[:lower:]')
case $(uname -m) in arm64|aarch64) arch=arm64 ;; x86_64|amd64) arch=amd64 ;; *) exit 1 ;; esac
case "$os" in linux|darwin) ;; *) exit 1 ;; esac
archive="fleetdiff_v0.7.0_${os}_${arch}.tar.gz"
base=https://github.com/llm-measurement/fleetdiff/releases/download/v0.7.0
for file in "$archive" SHA256SUMS provenance.jsonl sbom.spdx.json; do
  curl --proto '=https' --tlsv1.2 -fL "$base/$file" -o "$file"
done
for file in "$archive" SHA256SUMS sbom.spdx.json; do
  gh attestation verify "$file" --bundle provenance.jsonl \
    --repo llm-measurement/fleetdiff \
    --signer-workflow llm-measurement/fleetdiff/.github/workflows/release.yml \
    --source-ref refs/tags/v0.7.0 --deny-self-hosted-runners
done
shasum -a 256 --ignore-missing -c SHA256SUMS
mkdir verified
tar -xzf "$archive" -C verified
./verified/fleetdiff --version

Release assets include SHA256SUMS, public Sigstore build provenance and an SPDX SBOM. The pinned release workflow records how they are produced. Provenance binds artifact bytes to a workflow and source ref; review the source and dependencies for your own deployment.

Verify the collector image and Helm chart

Use trusted Cosign tooling. Both the v0.3.2 image and chart 0.3.4 were signed by the collector release workflow below. Verify their immutable OCI digests before pulling or deploying; these commands perform signature and build-provenance checks without starting a container or changing a cluster.

set -eu
identity=https://github.com/llm-measurement/otelcol-genai-sketches/.github/workflows/release.yml@refs/tags/v0.3.2
image=ghcr.io/llm-measurement/otelcol-genai-sketches@sha256:f30001c845e4da7c14f97357eb0dcfa615e267cf84cbc18794808ac7c98ad933
chart=ghcr.io/llm-measurement/charts/otelcol-genai-sketches@sha256:5be83ca0ce24e5509d0bcdbf45008f16ca5bc09d0422a5c3d4526368a831b735
for artifact in "$image" "$chart"; do
  cosign verify --certificate-identity "$identity" \
    --certificate-oidc-issuer https://token.actions.githubusercontent.com "$artifact"
  cosign verify-attestation --type slsaprovenance1 \
    --certificate-identity "$identity" \
    --certificate-oidc-issuer https://token.actions.githubusercontent.com "$artifact"
done

The collector release publishes image and chart digests, SHA256SUMS and an SPDX SBOM index for both image platforms. The signed image index binds the platform SBOM content through OCI digests; the downloaded checksum file alone is an integrity check, not the authentication step. See Deployment for anonymous pulls, provenance verification and Helm installation, and the release workflow for the build.

Repository controls

Checked October 11, 2026 for the three tool repositories: active main-branch rules require signed commits, the commit-signature check and DCO sign-off. Release-tag rules block updates and deletion. Secret scanning, push protection and private vulnerability reporting are enabled.

The dated settings record retains the checked values. Repository administrators can recheck secret-scanning and push-protection settings using GitHub's repository API (security_and_analysis), and reporting status through the private-reporting API. Settings can change; the linked rules show the current state.

License and stability

All three tools are pre-1.0; the collector's traces-to-metrics component is alpha. Pin exact tool versions and image digests and test upgrades on representative inputs. Read the collector's Support policy and Security policy, plus fleetdiff and sketchkit security policies.

The tools use Apache-2.0: fleetdiff license, collector license, sketchkit license.