Software Supply Chain Integrity in DevOps: Provenance, Attestations, and Tamper-Resistant Build Pipelines

research-article
Received: Apr 10, 2022
Published: Jul 2, 2022
Authors:

Abstract

Modern delivery pipelines depend on third-party dependencies, build tools, and container ecosystems, expanding the attack surface of software supply chains. This research develops an integrity-first build pipeline model based on verifiable provenance, signed attestations, and artifact immutability. The paper evaluates approaches to dependency pinning, reproducible builds, and secure artifact promotion across environments. Findings indicate that integrating attestations into release workflows substantially reduces exposure to dependency substitution and artifact tampering while improving traceability for incident response.

Cite this article

(2022). Software Supply Chain Integrity in DevOps: Provenance, Attestations, and Tamper-Resistant Build Pipelines. Research Explorations in Global Knowledge & Technology (REGKT), 1 (3). Retrieved from https://regkt.com/article.php?id=774&slug=software-supply-chain-integrity-devops-provenance-attestations-tamper-resistant-build-pipelines

Premium Membership Required

You need a premium account to view or download this article.

Become Premium