Evidence limitation
Build provenance is not runtime operation
Direct limitation
It does not prove that the same artifact is deployed, configured correctly, reachable, authorized or currently performing its function.
Artifact or claim that may be supported
Supply-chain provenance can support how an artifact was built and by which process.
What the evidence does not establish
It does not prove that the same artifact is deployed, configured correctly, reachable, authorized or currently performing its function.
Additional evidence required
Release evidence can be mistaken for service evidence.
Mitigation
Bind build provenance to deployment records, runtime measurement, service observation and authorized state transitions.
Supporting sources
- Supply-chain Levels for Software Artifacts (SLSA) Specification v1.2 — OpenSSF; SLSA v1.2; Approved. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
- in-toto Attestation Framework — in-toto project; Current project framework; Open standard; CNCF graduated project. Exact claim-support entries: 1. Revalidated 2026-08-14T22:04:09Z.