H.11.2 Artifact Identity

recommended
Reading progress1 missing

1 required article is still unread. Reading it first is recommended, but not required.

Article in preparation — showing conspect notes

Artifact identity answers which bytes were produced from which build context.

  • Record the source, configuration, toolchain, build, and provenance identity required for diagnosis and promotion.
  • Keep timestamps and CI details out of build identity unless they are deliberate product inputs.
  • Attach richer release metadata only to outputs that consume it so unrelated graph slices retain reuse.
  • Choose embedded, sidecar, registry, manifest, and release-record surfaces from consumer and incident needs.
  • Keep artifact identity distinct from a consumer-facing version and from the complete delivery trace.