SBOM, Provenance, and Build Lab
Create an isolated build with locked inputs, machine-readable SBOM, immutable digest, signing, provenance, independent verification, and reproducibility analysis.
Required evidence
Submit threat paths, machine-readable inventory and provenance, verified identities and digests, policy decisions, negative tampering test, exception lifecycle, recovery evidence, and residual risk. A badge or scanner report without verification does not pass.
Oral defense
Trace running bytes to reviewed source, demonstrate a failed tampering attempt, explain the verifier trust root, and execute revocation plus clean rebuild.
Source backbone
Use SLSA, NIST SSDF, Sigstore, Kubernetes admission documentation, and Building Secure and Reliable Systems.