Build Provenance

Back to SLSA Framework

Metadata that describes how an artifact was built: what source code, what build system, what inputs, and what configuration. Provenance attestations provide a verifiable record that enables consumers to trust that an artifact was built from known, unmodified source.

supply-chain-security slsa provenance