{
  "canonicalUrl": "https://xn--mwe.com/evidence/limitations/build-provenance-is-not-runtime-operation/",
  "claim": "Supply-chain provenance can support how an artifact was built and by which process.",
  "claimStatus": "PROJECT DOCTRINE",
  "consequence": "Release evidence can be mistaken for service evidence.",
  "correctionStatus": "CURRENT K05 RELEASE",
  "id": "LIM-K02-006",
  "lastReviewed": "2026-08-16",
  "limitation": "It does not prove that the same artifact is deployed, configured correctly, reachable, authorized or currently performing its function.",
  "machineRecordUrl": "https://xn--mwe.com/data/evidence/limitations/build-provenance-is-not-runtime-operation.json",
  "mitigation": "Bind build provenance to deployment records, runtime measurement, service observation and authorized state transitions.",
  "name": "Build provenance is not runtime operation",
  "releaseId": "K12-2026-08-16",
  "researchCutoff": "2026-08-16",
  "slug": "build-provenance-is-not-runtime-operation",
  "sourceIds": [
    "SRC-SLSA",
    "SRC-IN-TOTO"
  ],
  "sourceRevalidatedAt": "2026-08-15T23:00:00Z",
  "status": "PROJECT DOCTRINE",
  "topic": "security-resilience",
  "type": "EvidenceLimitation"
}
