attested-delivery
Every artifact provably identical to what was validated. No exceptions.
The core invariant
Section titled “The core invariant”An artifact reaches consumers only if it is byte-identical to what was validated, carries re-verifiable attestations (SLSA provenance, cosign signature, SBOM, vulnerability report), and publication is fail-closed gated on verification.
What you will find here
Section titled “What you will find here”The documentation is organized by Diátaxis — learning, tasks, reference, and understanding kept separate.
- Ecosystem Hub — the map of the whole ecosystem: every repo, template, and tool, with links out to each one’s own docs.
- Tutorial — verify your first attested release, hands-on, from a clean workstation.
- How-to Guides — onboard a repo to the quality gates, verify a release independently, and promote a build by digest.
- Reference — the central reusable workflows, the signing/verification seam, and the catalog-updater, contract by contract.
- Concepts — focused articles on the design decisions behind attested delivery: digest identity, attestation survival across registry hops, admission enforcement, SLSA levels, SBOMs, supply-chain hazards, DORA, AI provenance, and pipeline observability.
- Specifications — formal specs for the promotion pipeline, interface contracts, production-readiness gates, and GitHub-native quality gates.
- Architecture Decisions — the ADRs recording the rationale behind every significant technical choice, from digest promotion to security tooling pins.