SLSA
Build Integrity

SLSA SUPCHAIN-1: Build Integrity - Source, Build, Provenance

Per Supply-chain Levels for Software Artifacts (SLSA) v1.0+: build integrity. Requirements include (a) Source - version controlled + auditable + (b) Build - scripted + isolated + parameterless + hermetic + reproducible + (c) Provenance - generated by isolated builder + complete attestation + cryptographically signed + (d) align with SLSA Build Levels L1-L4.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.