Glossary · Security & governance

Provenance Attestation

Authenticated, machine-readable metadata that binds an artifact to claims about how, where, when, and from which inputs it was produced.

Why it matters

It lets automated policy and reviewers verify supply-chain claims instead of trusting an unsigned build note.

In practice

Generate an attestation in the build system, bind it to artifact digests, sign it with a controlled identity, and verify it before release.

Common confusion

A signature identifies the attester and protects integrity; it does not prove that every claim inside the attestation is true.

Related terms

Sources

Browse the learning paths to see this term in context — every lesson is free to read.