← Home

Provenance

This site is built deterministically from versioned sources and validated at every boundary — the same discipline the work itself argues for. Here's what produced and checked this artifact.

Provenance chain

The build reads as an in-toto / SLSA-style provenance: declared materials, a checked build process, and a signed subject. Each link is verified; the last is the artifact itself.

  1. Subject — signed

    commit 706757a · 2026-07-27 · bdelanghe/site

    Real in-toto Statement/v1 + SLSA provenance (attestation.intoto.json), keyless-signed via Sigstore — a one-build Fulcio certificate minted from this workflow's GitHub OIDC identity, logged in the public Rekor transparency log — this build's entry. No held key. The whole built site is content-addressed (site.sha256) and signed too, and pushed to GHCR as a pullable, signed OCI artifact. See provenance.json for digests, Rekor entries, and verify/pull recipes. This proves who built the site and that it is intact.

    Authorized. Production is not deployed straight from a build: each version is first uploaded as an un-served preview, reviewed, and promoted to production only on required human approval (the site-promote environment). The exact reviewed, signed version is what goes live — so the live site is not just intact, its promotion was authorized.