CI/CD Platform · View 14 of 22 · Runtime
Decisions
- The resolved dependency set is recorded as data, not inferred later from a lockfile. It is an input to provenance and to the dependency scan, and both need to agree on what was actually fetched.
- A critical scan finding blocks tag movement, not the build. The artefact still exists, still carries its provenance, and is quarantined rather than deleted — a deleted artefact cannot be investigated.
- Cache restore verifies integrity and treats a verification failure as a miss. A poisoned entry costs a slow build, never a compromised one.
Realisation
- Dependencies resolved through the platform's mirror, so what a build pulled is both recorded and available during an upstream outage.
- Provenance and SBOM signed by the control-plane attestor with a KMS-held key and appended to the transparency log.
Risks
- A pipeline author can add a step that fetches code at build time and defeats the recorded dependency set. Egress policy is the only real control here, and it must be on by default.