fadaly.net/work/attestchain
SUPPLY CHAIN
PROVENANCE.
14 build artifacts attested via SLSA v1.0 Level 3.
4 missing a fully signed provenance statement.
1 attested with a signing key that expired 2 months ago.
An artifact without provenance is an artifact you can't defend in court.
AC-008 · payment-service:v4.1
EXPIRED KEY
Provenance signed 2025-09-12 with key revoked 2025-09-15.
Resign with current key, re-publish attestation, audit chain.