Skip to main content

Selective Reading Guide

Full-book reading is not required. Use SLSA and in-toto for provenance, Sigstore for signing, NIST SSDF for lifecycle practices, and Building Secure and Reliable Systems for platform operations.

Required evidence

Submit authorized pipeline configuration, inventory, artifact and provenance identifiers, verification output, injected failure, policy decision, remediation, and residual risk. A green build without trustworthy identity and traceability does not pass.

Oral defense

Trace source to runtime, explain which claim each artifact proves, demonstrate rejection of a substitution, and state the response when trust material is revoked.

Source backbone

Use SLSA, NIST SSDF, in-toto, and Sigstore.