Software Source, Dependency and Build Provenance

archimatev1

/01 Views

Source and dependency stewardshiparchimate
Logical source-to-build component separationarchimate
Independent reproduction and provenance generationarchimate
Build runtime trust boundaryarchimate
Source-to-build qualificationarchimate
Build to accepted immutable candidatearchimate
Approved source identityarchimate
Complete pinned software inputarchimate
Manifest and resolved grapharchimate
Provenance-backed SBOM generationarchimate
Licensing restrictions and decisionsarchimate
Context-specific finding dispositionarchimate
Resolved external package input boundaryarchimate
Build inputs and toolchain custodyarchimate
Attributed construction and outputarchimate
Independent rebuild and evidencearchimate
Bind evidence to exact output digestarchimate
Accepted artifact and evidencearchimate
Unknown source is quarantinedarchimate
Untrusted dependency change blocks releasearchimate
Unsafe build environment blocks promotionarchimate
Output mismatch reopens qualificationarchimate
Negative policy and reproducibility outcomesarchimate
Remediated input is re-reviewedarchimate
Source and dependency tamperingarchimate
Builder isolation riskarchimate
Evidence and candidate bindingarchimate
Input review authorityarchimate
Risk owner and license policyarchimate
Independent test custodyarchimate
Build runtime operationsarchimate
Validated complete build inputsarchimate
Independent repeatability objectivearchimate
Enterprise source-to-build processarchimate
Complete dependency evidencearchimate
Repeatability evidence measurearchimate
Bounded build trust environmentarchimate
Downstream consumer of verified candidatearchimate

/02 About

Trace reviewed immutable source, pinned transitive materials, build isolation, SBOM coverage, repeatability and candidate-bound provenance evidence.

Purpose: provide a technology-neutral first-principles architecture for producing attributable software deliverables from controlled source and materials. Distinguish source authorization, direct and transitive dependency closure, license and vulnerability assessment, isolated construction, independent repeatability verification and statements bound to the exact artifact digest. Trust invariants: a branch or tag name is not sufficient source integrity; all material dependencies must be pinned and attributed or recorded as unresolved. A component inventory represents assessed coverage, not a proof of completeness. Builder identity, recipe, parameters and privilege boundaries must be documented. A reproducibility claim requires independently comparable outputs under defined conditions; unexplained differences prohibit that claim. A signed provenance statement identifies a subject and builder but does not establish that source code is safe. Failure conditions: unknown source authorization, dependency drift, contaminated execution, failing legal/security risk disposition or divergent independent output causes an explicit quarantine and requalification. The repair loop returns to intake; none of these conditions silently result in a trusted candidate. Limitations: reference architecture, not a signed attestation implementation, guaranteed hermetic builder, software bill generation product, legal license opinion, or proof of build equivalence. Adopters must implement source identity, key protection, dependency version/digest rules, test criteria, vulnerability relevance, explicit exception authority and independently verifiable evidence.

Curated · operations · CC-BY-4.0 · Published by Lattix · 62 elements · 91 relationships · validated on publish

/03 Contents

Role
Source change authority, Dependency stewardship authority, Build execution authority, Independent build assurance assessor
Business Actor
Downstream artifact consumer
Capability
Produce attributable software artifacts
Process
Qualify and construct software candidate
Application
Logical trusted software construction system
Application Component
Source authenticity and review gateway, Dependency resolution and pinning boundary, Software component inventory generator, Dependency and policy evaluation boundary, Constrained build execution engine, Independent output comparison verifier, Provenance and quality statement generator, Immutable candidate publication interface
Trust Boundary
Build execution trust boundary
Node
Isolated build execution runtime
Business Object
Immutable source snapshot and revision, Reviewed source authorization record, Pinned build recipe and work definition, Declared direct dependency manifest, Exact dependency identity and lock record, Resolved transitive dependency graph, Artifact-scoped software bill of materials, Vulnerability and exploitability findings, License and distribution decision evidence, Source and build assurance test evidence, Attributed build operation record
Artifact
Identified build toolchain content, Resolved external dependency content, Content-addressed build output candidate, Signed or attributable provenance statement
Requirement
Complete traceable build-input requirement, Independent repeatability assessment requirement
Constraint
Approved immutable source requirement, Exact dependency content and origin requirement, Isolation and limited credential exposure
Policy
Dependency license and distribution policy, Vulnerability and exposure disposition policy
Control
Source and material tamper safeguard, Build environment and output protection, Provenance subject and evidence binding control
Risk
Compromised or incomplete software materials, Untrusted construction environment exposure
Activity
Validate requested source and review, Resolve exact transitive inputs, Generate artifact-scoped dependency inventory, Evaluate vulnerability and license findings, Execute attributed constrained build, Verify independent output correspondence, Bind attestation to output content identity, Release verified candidate to immutable store, Block and preserve unsafe candidate evidence, Repair input, environment or build deficiency
Business Event
Source identity or authorization unverified, Unexpected dependency content drift, Builder trust boundary compromise detected, Independent build comparison mismatch
Measure
Transitive dependency identification coverage, Build repeatability and output equivalence
Outcome
Attributable evidence-supported candidate