Skip to main content

Worked Examples

Trace a dependency from manifest to deployed process; generate an SBOM and VEX decision; compare unsigned and signed artifacts; analyze a CI token escalation; and write a SLSA-aligned promotion policy.

Required evidence

Submit authorized pipeline configuration, inventory, artifact and provenance identifiers, verification output, injected failure, policy decision, remediation, and residual risk. A green build without trustworthy identity and traceability does not pass.

Oral defense

Trace source to runtime, explain which claim each artifact proves, demonstrate rejection of a substitution, and state the response when trust material is revoked.

Source backbone

Use SLSA, NIST SSDF, in-toto, and Sigstore.