H.9.4 Supply Chain
recommendedReading progress2 helpful
Prerequisites0/2 complete
- Not completeH.5.6Dependency Intakehelpful
Intake establishes the dependency source, version, maintenance, and license evidence security controls build upon.
- Not complete6.7.6Build Provenance and Attestationshelpful
Bazel build provenance supplies one technical attestation in the broader supply-chain model.
Articles read
Helpful reading is optional.
Article in preparation — showing conspect notes
Supply-chain security asks whether inputs, build authority, and produced artifacts can be trusted for their intended use.
- Verify dependency source and integrity, allowed registries or mirrors, update authority, vulnerabilities, and license obligations.
- Separate builder identity, artifact signing, provenance attestations, SBOMs, registry authorization, and promotion policy.
- State which claim each signature or attestation binds and which compromise it does not detect.
- Define response to vulnerable, malicious, abandoned, revoked, or unverifiable inputs and artifacts.
- Preserve evidence required by regulated or external consumers without treating compliance paperwork as proof of runtime safety.