Code provenance
Verifiable information about a software artifact stating where, when and how it was produced.
Official source: Provenance — SLSA v1.0 →
The specification makes this checkable rather than declarative: a signed predicate names the build platform trusted to have run the build, and records the external parameters fed into it — parameters the model treats as untrusted and requires to be disclosed. The point is that a consumer verifies the claim instead of believing the publisher.
Sources 1 source on record · Automated review 3 angles
Sources
What this page is based on — every source is verified and links out so you can check it yourself.
- Verified / official
- Provisional
- Out of date