H.9.4 Supply Chain

recommended
Reading progress2 helpful
Article in preparation — showing conspect notes

Supply-chain security asks whether inputs, build authority, and produced artifacts can be trusted for their intended use.

  • Verify dependency source and integrity, allowed registries or mirrors, update authority, vulnerabilities, and license obligations.
  • Separate builder identity, artifact signing, provenance attestations, SBOMs, registry authorization, and promotion policy.
  • State which claim each signature or attestation binds and which compromise it does not detect.
  • Define response to vulnerable, malicious, abandoned, revoked, or unverifiable inputs and artifacts.
  • Preserve evidence required by regulated or external consumers without treating compliance paperwork as proof of runtime safety.