Supply-Chain Provenance
SBOMs, signed artifacts, attestation, and knowing what actually went into a build.
4 to work through
-
intermediate
Your pipeline now generates an SBOM for every build. A critical vulnerability is announced in a transitive dependency. Can you answer the question that matters?
2 min answer -
advanced
An auditor asks you to prove that the container running in production is the one that passed security scanning three weeks ago. What must be true?
2 min answer -
advanced
The xz-utils backdoor disclosed on 29 March 2024 (CVE-2024-3094) was present in the release tarballs for versions 5.6.0 and 5.6.1 but not in the equivalent state of the public git repository: the malicious build-to-host.m4 macro shipped only in the distributed archive and activated a payload hidden in test fixtures during the build. Which assumption in a normal supply-chain pipeline does this defeat, and what would have caught it?
3 min answer -
advanced
What does provenance add beyond signing, and what makes it usable rather than ceremonial?
2 min answer
3 terms in this topic
Build Attestation
A signed statement about how an artifact was produced — by which builder from which source — that a deployment gate can verify rather than trust.
conceptRelease Tarball Divergence
The gap between a project's reviewed source repository and the source archive that downstream actually builds, which is a trust boundary most supply-…
toolSoftware Bill of Materials
A machine-readable inventory of every component and dependency inside a built artifact.
Neighbouring topics
Delivery & Release Engineering
General material on getting a change from commit to production safely and often.
Pipeline Architecture
Stages, fan-out, caching, and the difference between a pipeline and a long script.
Build Reproducibility
Pinned inputs and hermetic builds, so one commit cannot produce two different artifacts.
Artifact Management
Immutable versioned outputs, promotion between repositories, and retention policy.
Environment Strategy
How many environments earn their cost, what each proves, and what none of them prove.
Branching Models
GitFlow, trunk and release branches as delivery constraints rather than Git preferences.
Continuous Integration Discipline
Integrating to the mainline daily, and the test speed and review culture that requires.
Deployment Strategies
Rolling, blue-green, canary and shadow, and the traffic and state each one assumes.
Progressive Delivery
Separating deploy from release, and exposing a change to users in controlled increments.
Rollback & Forward Fix
When reversing is genuinely possible, and designing so that it usually is.
Database Migration Under CD
Expand-contract, backwards-compatible schema change, and migrations that cannot roll back.
GitOps
Declared desired state in version control, with a reconciler closing the gap continuously.
IaC Modules & Drift
Reusable infrastructure modules, state ownership, and detecting what changed out of band.
Policy as Code
Encoding standards as automated admission and plan-time checks instead of review comments.
Pipeline Secrets
Short-lived credentials, workload identity, and why the CI system is a prime target.
Deployment Gates
Automated verification between stages, and the difference between a gate and a delay.
Flow Metrics
Work in progress, flow time and flow efficiency — where a change waits rather than moves.
Change Management vs CD
Reconciling CAB-era controls with continuous delivery without pretending either away.
Multi-Region Rollout
Ordering regions, bake time, and stopping a bad change before it becomes global.