Provenance & SBOM

Prove where artifacts came from (SLSA, OS hash-chains) and produce the bills of materials auditors and IR teams ask for (CycloneDX, CSV, BOM inspector).

A risky package is one problem; not knowing where it came from is another. Provenance tells you whether you can trust an artifact’s origin; the SBOM tells you what you actually have. This section covers verifying build provenance (SLSA) and OS-package hash-chains, exporting standards-compliant bills of materials (CycloneDX and CSV), and investigating a specific artifact’s history with the BOM inspector.

Provenance is a policy input, not just a report. A failed SLSA or hash-chain check refuses the install — wire it up in Policy & Enforcement.

Where to next

To answer “are we affected by CVE-X?” across inventory, see Remediation & Patching.