By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Supply Chain Security: Provenance Tools Becoming Standard in Developer Platforms
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Supply Chain Security: Provenance Tools Becoming Standard in Developer Platforms
News

Supply Chain Security: Provenance Tools Becoming Standard in Developer Platforms

News Room
Last updated: 2025/08/19 at 5:21 AM
News Room Published 19 August 2025
Share
SHARE

Software provenance is gaining new importance as organizations look for ways to secure their supply chains against tampering and comply with emerging standards like SLSA. In a recent blog post, HashiCorp highlighted how its HCP Packer service captures build metadata and SBOMs to support Supply-chain Levels for Software Artifacts (SLSA) Level 1 compliance. 

Attacks such as SolarWinds and CodeCov showed how a compromised build process can allow malicious code to reach thousands of downstream users . Regulators have responded: in the U.S., Executive Order 14028 requires federal software suppliers to provide verifiable provenance, while Europe’s Cyber Resilience Act imposes similar obligations.

For practitioners, the implications are clear: Being able to prove exactly how software was built is becoming essential.

Two open source projects have shaped how the industry approaches provenance: Sigstore provides cryptographic signing and transparency infrastructure designed for broad ecosystem adoption. The model has gained traction across major ecosystems such as npm, PyPI, and Kubernetes, where provenance verification is now increasingly automated.

in-toto takes a different approach: it secures the entire pipeline by generating signed attestations for each step, verifying ‘who did what, when’ across builds, tests, and releases . Its layout model defines the expected steps and trusted actors, making tampering visible if any stage is skipped or altered.

HashiCorp’s Packer has long included metadata capture – recording details such as CLI and plugin versions, commit SHAs, and CI/CD pipeline context. More recently it added SBOM generation. What has changed is the positioning: HashiCorp is now presenting these features as a core provenance capability, emphasizing that HCP Packer can give teams a start on compliance out of the box.

Packer is not alone in this space. GitHub has introduced artifact attestations and SBOM generation as part of its Actions platform, allowing teams to generate signed provenance aligned with the SLSA specification. Red Hat’s Konflux, a Kubernetes-based build service, issues in-toto attestations as part of its pipelines, tying them to policy enforcement for a full trust chain.

This positioning highlights how vendors are still reliant on OSS tools to traverse the levels of the SLSA framework. Higher levels require stronger guarantees. Level 2 demands signed, tamper-resistant provenance, where Sigstore’s signing and transparency log are a natural fit. Levels 3 and 4 add verified source control and isolated build environments, where in-toto’s attestations help ensure every pipeline step follows policy.

Despite growing support, adoption isn’t trivial. Provenance formats are still evolving, and SBOMs often differ sharply depending on the tool or stage of generation, complicating comparison and verification. In addition, a qualitative study analyzing 1,523 GitHub issues across 233 repositories found that practitioners face significant barriers when adopting the SLSA framework—including “complex implementation” and “unclear communication” of requirements and processes

For engineering teams, the benefits are practical as well as regulatory. Provenance provides a clearer picture of the build process, helping with debugging, incident response, and audit preparation.

Provenance is increasingly being built in as a standard feature rather than an add-on. Open source projects like Sigstore and in-toto continue to define common practices, while vendors  are integrating provenance into their platforms to make it easier to adopt. The level of assurance still varies, but usage is broadening across the software supply chain.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article XREAL secures $60 million to expand AR devices production · TechNode
Next Article CATL profit growth slows in 2H amid fierce competition · TechNode
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

I Make Fillable Forms in Word—And It’s Easier Than You Think
Computing
You Can Get This Asus TUF 32 4K Monitor at an All-New Low Price Right Now
News
Kenya’s Craydel enters Burundi and Tanzania in latest Africa expansion
Computing
The Mysterious Origins of the Most Energetic Neutrino Ever Detected
Gadget

You Might also Like

News

You Can Get This Asus TUF 32 4K Monitor at an All-New Low Price Right Now

3 Min Read
News

The 11 Best Historical Epics Streaming on Netflix—Ranked

14 Min Read
News

London must escape the doom spiral to win the AI race – UKTN

1 Min Read
News

QuickBooks Online vs. Xero: Which Will Make Your Books a Breeze?

13 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?