SLSA Build Provenance¶
Community, S. (2023). SLSA Build Provenance. SLSA Specification v1.0.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Provenance Header or Manifest
- Attached to the image is a provenance manifest in the style of a software bill of materials plus build attestation: it lists the source repository and commit, the build system and time, the exact component versions bundled, the owner, and a SHA-256 digest signed by the build pipeline.
This sourceSpecifies repository-linked source inputs, builder identity, and build timing as provenance fields.
- Attached to the image is a provenance manifest in the style of a software bill of materials plus build attestation: it lists the source repository and commit, the build system and time, the exact component versions bundled, the owner, and a SHA-256 digest signed by the build pipeline.
Verification¶
Does it exist? Not checked yet. This entry carries no identifier to resolve. It was extracted from the citation as written in the article, normalized, and deduplicated against the rest of the registry.
Does it back the claim? Not recorded. The single citation of this work carries no recorded support check.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:126e817c3336 · see in the full table