Glossary · Security & governance
Provenance Attestation
Authenticated, machine-readable metadata that binds an artifact to claims about how, where, when, and from which inputs it was produced.
Why it matters
It lets automated policy and reviewers verify supply-chain claims instead of trusting an unsigned build note.
In practice
Generate an attestation in the build system, bind it to artifact digests, sign it with a controlled identity, and verify it before release.
Common confusion
A signature identifies the attester and protects integrity; it does not prove that every claim inside the attestation is true.
Related terms
Sources
Browse the learning paths to see this term in context — every lesson is free to read.