Secure Software Supply Chain — verifiable delivery
c4v1/01 Views
/02 About
Trusted source-to-artifact-to-deployment pipeline with component provenance, isolated builds, attestations, verification, supply-chain risk and rollback.
Purpose: Trusted source-to-artifact-to-deployment pipeline with component provenance, isolated builds, attestations, verification, supply-chain risk and rollback. Architecture scope: independently reconstructed reference responsibilities, operational flows, policy decisions, assurance concerns, exception pathways and security boundaries. Grouped viewpoints describe coherent service or activity sequences. Focused trace views expose inter-domain obligations and information exchanges. Adoption: refine control and data-flow semantics to the enterprise ecosystem; map resource owners, role and workload identities, interfaces, failure policies, information classification, privacy obligations, deployment options and operational evidence. Reference elements alone do not establish an authorization, compliance result, formal proof, cryptographic assurance, or production readiness. Public conceptual basis: https://csrc.nist.gov/pubs/sp/800/218/final. This is an original Arq vendor-neutral interpretation, not an official implementation diagram or an endorsed/certified solution.
Published by Lattix · 20 elements · 23 relationships · validated on publish
/03 Contents
- Business Actor
- Developer or producer
- Application
- Source repository, Production runtime
- Application Component
- Dependency and license analysis, Isolated build service, Security and quality verification, Provenance and signing service, Release promotion control, Artifact attestation verifier, Deployment authorization gate, Continuous policy check
- Data Store
- Component inventory and SBOM, Signed artifact registry, Release assurance evidence
- Activity
- Ingest vulnerability advisories, Assess affected artifacts, Rebuild and re-attest, Deploy verified remediation
- Role
- Security assurance owner
- Policy
- Approved build and dependency policy