Software Source, Dependency and Build Provenance
archimatev1/01 Views
/02 About
Trace reviewed immutable source, pinned transitive materials, build isolation, SBOM coverage, repeatability and candidate-bound provenance evidence.
Purpose: provide a technology-neutral first-principles architecture for producing attributable software deliverables from controlled source and materials. Distinguish source authorization, direct and transitive dependency closure, license and vulnerability assessment, isolated construction, independent repeatability verification and statements bound to the exact artifact digest. Trust invariants: a branch or tag name is not sufficient source integrity; all material dependencies must be pinned and attributed or recorded as unresolved. A component inventory represents assessed coverage, not a proof of completeness. Builder identity, recipe, parameters and privilege boundaries must be documented. A reproducibility claim requires independently comparable outputs under defined conditions; unexplained differences prohibit that claim. A signed provenance statement identifies a subject and builder but does not establish that source code is safe. Failure conditions: unknown source authorization, dependency drift, contaminated execution, failing legal/security risk disposition or divergent independent output causes an explicit quarantine and requalification. The repair loop returns to intake; none of these conditions silently result in a trusted candidate. Limitations: reference architecture, not a signed attestation implementation, guaranteed hermetic builder, software bill generation product, legal license opinion, or proof of build equivalence. Adopters must implement source identity, key protection, dependency version/digest rules, test criteria, vulnerability relevance, explicit exception authority and independently verifiable evidence.
Curated · operations · CC-BY-4.0 · Published by Lattix · 62 elements · 91 relationships · validated on publish
/03 Contents
- Role
- Source change authority, Dependency stewardship authority, Build execution authority, Independent build assurance assessor
- Business Actor
- Downstream artifact consumer
- Capability
- Produce attributable software artifacts
- Process
- Qualify and construct software candidate
- Application
- Logical trusted software construction system
- Application Component
- Source authenticity and review gateway, Dependency resolution and pinning boundary, Software component inventory generator, Dependency and policy evaluation boundary, Constrained build execution engine, Independent output comparison verifier, Provenance and quality statement generator, Immutable candidate publication interface
- Trust Boundary
- Build execution trust boundary
- Node
- Isolated build execution runtime
- Business Object
- Immutable source snapshot and revision, Reviewed source authorization record, Pinned build recipe and work definition, Declared direct dependency manifest, Exact dependency identity and lock record, Resolved transitive dependency graph, Artifact-scoped software bill of materials, Vulnerability and exploitability findings, License and distribution decision evidence, Source and build assurance test evidence, Attributed build operation record
- Artifact
- Identified build toolchain content, Resolved external dependency content, Content-addressed build output candidate, Signed or attributable provenance statement
- Requirement
- Complete traceable build-input requirement, Independent repeatability assessment requirement
- Constraint
- Approved immutable source requirement, Exact dependency content and origin requirement, Isolation and limited credential exposure
- Policy
- Dependency license and distribution policy, Vulnerability and exposure disposition policy
- Control
- Source and material tamper safeguard, Build environment and output protection, Provenance subject and evidence binding control
- Risk
- Compromised or incomplete software materials, Untrusted construction environment exposure
- Activity
- Validate requested source and review, Resolve exact transitive inputs, Generate artifact-scoped dependency inventory, Evaluate vulnerability and license findings, Execute attributed constrained build, Verify independent output correspondence, Bind attestation to output content identity, Release verified candidate to immutable store, Block and preserve unsafe candidate evidence, Repair input, environment or build deficiency
- Business Event
- Source identity or authorization unverified, Unexpected dependency content drift, Builder trust boundary compromise detected, Independent build comparison mismatch
- Measure
- Transitive dependency identification coverage, Build repeatability and output equivalence
- Outcome
- Attributable evidence-supported candidate