Provenance & SBOM
Prove where artifacts came from (SLSA, OS hash-chains) and produce the bills of materials auditors and IR teams ask for (CycloneDX, CSV, BOM inspector).
A risky package is one problem; not knowing where it came from is another. Provenance tells you whether you can trust an artifact’s origin; the SBOM tells you what you actually have. This section covers verifying build provenance (SLSA) and OS-package hash-chains, exporting standards-compliant bills of materials (CycloneDX and CSV), and investigating a specific artifact’s history with the BOM inspector.
Where to next
To answer “are we affected by CVE-X?” across inventory, see Remediation & Patching.