Decide whether the inventory, advisory disposition, provenance, and admission result refer to the same release bytes. A signed statement or clean scan is insufficient when its subject changed during promotion.
Review these lessons
- SBOM scope: distinguish build inputs from shipped components
- SBOM binding: keep the inventory attached to the tested digest
- Package identity: verify advisory matches before changing a release
- VEX decisions: bind a not-affected claim to evidence and expiry
- Build provenance: verify who asserted how the artifact was made
- Admission verification: compare the running image with approved evidence
- Base-image refresh: rebuild and retest when inherited bytes change
- Registry evidence retention: keep referrers with the release digest
Other checks
Common Mistakes
- Do not bind release evidence to a mutable tag.
- Do not assume destination registries retain source-side referrers.
