Resources
Use locked package managers, SBOM generators, provenance and attestation tools, signing and verification, isolated CI runners, policy engines, admission controls, secret managers, drift detection, and vulnerability tracking.
Required evidence
Submit authorized pipeline configuration, inventory, artifact and provenance identifiers, verification output, injected failure, policy decision, remediation, and residual risk. A green build without trustworthy identity and traceability does not pass.
Oral defense
Trace source to runtime, explain which claim each artifact proves, demonstrate rejection of a substitution, and state the response when trust material is revoked.