Build provenance: connect artifacts to their build
Understand build provenance and create a signed receipt of build steps, declared inputs and resulting software artifacts.
Understand what a build records, what a receipt signs and what a recipient can verify.
Understand build provenance and create a signed receipt of build steps, declared inputs and resulting software artifacts.
Bind an attestation to a software artifact, identify what is signed and verify the statement using trusted keys.
Verify a signed receipt without the build system: required files, trusted keys and Continuum Attest CLI checks.
Distinguish an SBOM, build provenance and artifact attestation to understand the records delivered with software.
Understand Continuum Attest exports using in-toto Statement v1, SLSA Provenance v1 and a DSSE envelope.
Place build provenance and signed attestations within software supply chain security and software artifact integrity.
CI status reports a result. Signed provenance provides a record recipients can connect to artifacts and verify independently.
Follow one release to understand the distinct roles of an SBOM, build provenance and a signed artifact attestation.
Keep signed receipts with artifacts and prepare independent verification, including in offline environments.
Distinguish the in-toto attestation framework, SLSA provenance and requirements, and Sigstore signing tools.
A digest compares files. Learn what additional context signed build provenance provides about software production.
Distinguish independent verification from trust in the build: signed receipts, available files and approved keys.