Secure Software Supply Chain — verifiable delivery

c4v1

/01 Views

Source and dependency provenancec4
Trusted build and artifact custodyc4
Release and runtime verificationc4
Vulnerability responsec4
Supply-chain governancec4
Source repository → Isolated build servicec4
Provenance and signing service → Artifact attestation verifierc4
Artifact attestation verifier → Signed artifact registryc4
Approved build and dependency policy → Deployment authorization gatec4
Dependency and license analysis → Assess affected artifactsc4
Security and quality verification → Continuous policy checkc4
Continuous policy check → Release promotion controlc4
Deployment authorization gate → Release assurance evidencec4

/02 About

Trusted source-to-artifact-to-deployment pipeline with component provenance, isolated builds, attestations, verification, supply-chain risk and rollback.

Purpose: Trusted source-to-artifact-to-deployment pipeline with component provenance, isolated builds, attestations, verification, supply-chain risk and rollback. Architecture scope: independently reconstructed reference responsibilities, operational flows, policy decisions, assurance concerns, exception pathways and security boundaries. Grouped viewpoints describe coherent service or activity sequences. Focused trace views expose inter-domain obligations and information exchanges. Adoption: refine control and data-flow semantics to the enterprise ecosystem; map resource owners, role and workload identities, interfaces, failure policies, information classification, privacy obligations, deployment options and operational evidence. Reference elements alone do not establish an authorization, compliance result, formal proof, cryptographic assurance, or production readiness. Public conceptual basis: https://csrc.nist.gov/pubs/sp/800/218/final. This is an original Arq vendor-neutral interpretation, not an official implementation diagram or an endorsed/certified solution.

Published by Lattix · 20 elements · 23 relationships · validated on publish

/03 Contents

Business Actor
Developer or producer
Application
Source repository, Production runtime
Application Component
Dependency and license analysis, Isolated build service, Security and quality verification, Provenance and signing service, Release promotion control, Artifact attestation verifier, Deployment authorization gate, Continuous policy check
Data Store
Component inventory and SBOM, Signed artifact registry, Release assurance evidence
Activity
Ingest vulnerability advisories, Assess affected artifacts, Rebuild and re-attest, Deploy verified remediation
Role
Security assurance owner
Policy
Approved build and dependency policy