Term Kind Topic What it is
Artifact Signing practice Supply Chain Security Cryptographically signing build outputs so that deployment can verify what is being run was produced by the expected pipeline from the expected source.
Build Provenance Artefact Attestation, SLSA Provenance practice Supply Chain Security A signed, verifiable statement of what was built, from which source, by which builder, with which dependencies - so a consumer can check that an artefact corresponds to reviewed source.
Reachability Triage Exploitability Prioritisation, Vulnerability Relevance practice Supply Chain Security Prioritising dependency vulnerabilities by whether the vulnerable code path is actually reachable and exploitable in your application, rather than by severity score - which is what makes vulnerability manageme…
Supply Chain Attestation SLSA, Provenance Attestation practice Supply Chain Security A signed statement about how an artifact was produced — from which source, by which builder, with which inputs — verified before deployment.