Provenance

build provenance, attestations, signatures and checksum coverage

CasesPassedFailedAdvisory
3300

Provenance

TEA’s object model is careful about identity, but identity is only worth something if a consumer can verify it: a checksum matches bytes to a record, a signature matches the record to a publisher, and an attestation describes the build that produced it. A publisher can conform to the object specification while supplying none of the three.

MeasureValue
Artifacts inspected118
Carrying a checksum118
Carrying a signature0
Carrying a media type118
With more than one immutable revision0
Signatures fetched0
Checksum algorithmCount
SHA-256118

Signatures are fetched, not verified: verification needs a trust root this suite has no way to establish, and inventing one would be worse than saying so.

provenance cases

CaseOperationStatusSchemaLatencyVerdict
118 of 118 artifacts carry a checksumprovenanceCoverage---pass
0 of 118 artifacts carry a signatureprovenanceCoverage---pass
118 of 118 artifacts carry a media typeprovenanceCoverage---pass

Detail

0 of 118 artifacts carry a signature

  • none do, so a consumer cannot verify who published the record

Back to the summary