Build & Provenance Integrity
Ensuring artefacts are built from the expected source, on a trusted platform, without tampering — and that the resulting provenance is verifiable by anyone downstream.
5 OpenSSF projects and publications help with Build Integrity, each with a one-sentence note on how. Prefer another way in? Browse by role →
OpenSSF Model Signing (OMS)
Attaches verifiable signatures to model artifacts, letting downstream users trace a model back to its origin.
Full breakdown
Repository Service for TUF (RSTUF)
Protects the distribution chain against rollback and man-in-the-middle attacks between repository and client.
Full breakdown
SBOMit
Binds in-toto and Witness attestations to SBOM entries so each component carries verifiable proof of how it was built.
Full breakdown
Sigstore
Records signatures in a transparency log, making artefact provenance independently auditable downstream.
Full breakdown
SLSA
Defines progressive levels for source, build, and provenance integrity so artefacts can be traced back to their origin.
Full breakdown