Term Kind Topic What it is
Artifact Signing practice Supply Chain Security Cryptographically signing build outputs so that deployment can verify what is being run was produced by the expected pipeline from the expected source.
Software Bill of Materials SBOM tool Supply Chain Security A machine-readable inventory of every component and dependency in a piece of software, including transitive ones, used to answer exposure questions quickly.