Not Just Ticking a Box β˜‘οΈ: Establishing Trust in Artifacts with Provenance πŸ”πŸ”—

Open Source Summit NA  •  June 25, 2025

When you consume a software artifact in production, do you know its provenance? Just as physical products have stamps and certifications documenting their origin and quality, software artifacts need verifiable provenance to establish trust in the supply chain.

This presentation explores how attestations and provenance data enable organizations to move beyond checkbox compliance toward genuine supply chain security. We demonstrate practical approaches to establishing trust in software artifacts through SLSA provenance, in-toto attestations, and the Konflux open source software factory.

Key Topics

  1. Software Supply Chain Security - Moving from physical world trust mechanisms to software artifact verification
  2. Attestations as Trust Anchors - Understanding in-toto attestation framework and verifiable claims
  3. SLSA Provenance - Implementing Supply-chain Levels for Software Artifacts
  4. Konflux Project - Building a security-first, cloud-native software factory with built-in attestation support

Speakers: Andrew McNamara & Ralph Bean, Red Hat