When you consume a software artifact in production, do you know its provenance? Just as physical products have stamps and certifications documenting their origin and quality, software artifacts need verifiable provenance to establish trust in the supply chain.
This presentation explores how attestations and provenance data enable organizations to move beyond checkbox compliance toward genuine supply chain security. We demonstrate practical approaches to establishing trust in software artifacts through SLSA provenance, in-toto attestations, and the Konflux open source software factory.
Speakers: Andrew McNamara & Ralph Bean, Red Hat