CI/CD Platform  ·  View 14 of 22  ·  Runtime

The Build Pipeline Inside One Run

Six stages. Signing is one of them, and cache save is the only stage a fork run skips.

Editable source SVG draw.io All views
Prepare Checkout at commit Restore cache integrity checked Resolve Resolve dependencies via mirror Record resolved set Build Compile Assemble image Verify Unit and integration tests Dependency scan Seal Upload by digest Sign provenance + SBOM Publish Move tag to digest Save cache trusted runs only warm inputs findings attached blocked on critical CI/CD Platform — The Build Pipeline Inside One Run Application we own Data store Security / platform Interface / broker synchronous failure / alternate Signing is a stage, not an afterthought, and cache save is the only stage an untrusted run skips. v 1.0 · owner Platform Engineering · date 2026-09

Decisions

  • The resolved dependency set is recorded as data, not inferred later from a lockfile. It is an input to provenance and to the dependency scan, and both need to agree on what was actually fetched.
  • A critical scan finding blocks tag movement, not the build. The artefact still exists, still carries its provenance, and is quarantined rather than deleted — a deleted artefact cannot be investigated.
  • Cache restore verifies integrity and treats a verification failure as a miss. A poisoned entry costs a slow build, never a compromised one.

Realisation

  • Dependencies resolved through the platform's mirror, so what a build pulled is both recorded and available during an upstream outage.
  • Provenance and SBOM signed by the control-plane attestor with a KMS-held key and appended to the transparency log.

Risks

  • A pipeline author can add a step that fetches code at build time and defeats the recorded dependency set. Egress policy is the only real control here, and it must be on by default.