Skip to content

attested-delivery

Every artifact provably identical to what was validated. No exceptions.

An artifact reaches consumers only if it is byte-identical to what was validated, carries re-verifiable attestations (SLSA provenance, cosign signature, SBOM, vulnerability report), and publication is fail-closed gated on verification.

The documentation is organized by Diátaxis — learning, tasks, reference, and understanding kept separate.

  • Ecosystem Hub — the map of the whole ecosystem: every repo, template, and tool, with links out to each one’s own docs.
  • Tutorial — verify your first attested release, hands-on, from a clean workstation.
  • How-to Guides — onboard a repo to the quality gates, verify a release independently, and promote a build by digest.
  • Reference — the central reusable workflows, the signing/verification seam, and the catalog-updater, contract by contract.
  • Concepts — focused articles on the design decisions behind attested delivery: digest identity, attestation survival across registry hops, admission enforcement, SLSA levels, SBOMs, supply-chain hazards, DORA, AI provenance, and pipeline observability.
  • Specifications — formal specs for the promotion pipeline, interface contracts, production-readiness gates, and GitHub-native quality gates.
  • Architecture Decisions — the ADRs recording the rationale behind every significant technical choice, from digest promotion to security tooling pins.