Release Security
Release artifacts must provide cryptographic proof of authenticity and tamper-resistance.
Requirements
- Digital Signatures: Binaries and container images signed with verifiable public keys.
- SBOM Inclusion: SPDX or CycloneDX SBOM manifests published alongside releases.
- Build Provenance: Verifiable SLSA build attestations proving generation in secure CI pipelines.