fadaly.net/work/attestchain
SUPPLY CHAIN

PROVENANCE.

14 build artifacts attested via SLSA v1.0 Level 3. 4 missing a fully signed provenance statement. 1 attested with a signing key that expired 2 months ago.

An artifact without provenance is an artifact you can't defend in court.

AC-008 · payment-service:v4.1 EXPIRED KEY
Provenance signed 2025-09-12 with key revoked 2025-09-15.
Resign with current key, re-publish attestation, audit chain.