Repro Bundle Profile (SLSA v1 + in-toto + DSSE)

Status

Purpose

Required bundle contents (per artifact)

  1. build_provenance.json with SLSA v1 predicate fields:
    • builder.id and builder.version
    • source binding (invocation and commit)
    • materials[] with pinned digests
    • canonicalized build command representation
    • pinned toolchain digest (@sha256:...)
  2. in_toto.link mapping materials to products with deterministic digests.
  3. DSSE signatures/envelopes for provenance and link payloads.
  4. Transparency evidence:
    • Online mode: Rekor entry metadata.
    • Offline mode: local checkpoint/tile bundle and verification metadata, including Rekor leaf hash (leafHash), path hashes, and checkpoint root.

Canonicalization policy (fail-closed)

Verification modes

Online mode

Offline mode

Promotion gate contract

Component ownership map

Test expectations