Provenance

Provenance records how an artefact was built: by what, from what source, with which dependencies, at what time.

It is what lets you answer, months later, whether a particular binary came from the commit you think it did. Without it, a supply chain investigation begins with reconstructing history from memory. It is becoming an expectation rather than a nicety, and it is cheap to produce at build time and impossible to add afterwards.

Checked against the primary source.

More on Software supply chain & DevSecOps