Files
llm-wiki/raw/official-docs/slsa-v1-provenance-schema.md
T

12 KiB

title, source_type, status, confidence, url, archive_url, tags, related_projects, related_branches, created, last_reviewed
title source_type status confidence url archive_url tags related_projects related_branches created last_reviewed
SLSA v1.0 Provenance Schema (Field Names) official-doc raw high https://slsa.dev/spec/v1.0/provenance
ca-supply-chain
slsa
provenance
in-toto
ca-skeleton-operational-contract
feature-build-release-supply-chain-contract
2026-05-22 2026-05-27

SLSA v1.0 Provenance Schema (Field Names)

Layer: raw/official-docs/ — SLSA v1.0 provenance predicate 의 정확 필드명 + in-toto Statement 래퍼 필드의 verbatim 캡처. ca-tmpl 약식 필드명 ↔ spec 필드명 매핑 근거.

Parent / 활용 branch (필수)

Branch 이 자료가 정당화하는 결정
raw/branch-notes/feature-build-release-supply-chain-contract ca-tmpl 약식 필드명 (build.config.source, build.invocation, materials) 을 spec 필드명 (buildDefinition.externalParameters, runDetails.metadata.invocationId, buildDefinition.resolvedDependencies) 으로 정정해야 한다는 결정의 근거 (G-E 후속 보강)

컨텍스트 / 왜 저장했는지

ca-tmpl feature-build-release-supply-chain-contract branch-note 는 SLSA provenance 항목을 약식/한국어 명칭으로 기록해 두었으나 (build.config.source, build.invocation, materials), SLSA v1.0 spec 의 실제 필드명은 다르다 (buildDefinition.externalParameters, runDetails.builder.id, runDetails.metadata.invocationId). slsa-verifier 등 도구는 spec 필드명을 그대로 검사하므로 약식 명명으로 provenance 를 생성하면 검증이 실패한다. G-E 후속 보강의 근거 자료로 보관.

출처 / Source

핵심 인용 / Key quotes (verbatim)

in-toto Statement 래퍼

[§Statement — _type] "Identifier for the schema of the Statement. Always https://in-toto.io/Statement/v1 for this version."

[§Statement — subject] "Set of software artifacts that the attestation applies to. Each element represents a single software artifact. Each element MUST have digest set."

[§Statement — predicateType] "URI identifying the type of the Predicate."

[§Statement — predicate] "Additional parameters of the Predicate. Unset is treated the same as set-but-empty. MAY be omitted if predicateType fully describes the predicate."

SLSA v1.0 Provenance Predicate

[§buildDefinition.buildType] "Identifies the template for how to perform the build and interpret the parameters and dependencies."

[§buildDefinition.externalParameters] "The parameters that are under external control, such as those set by a user or tenant of the build platform."

[§buildDefinition.internalParameters] "The parameters that are under the control of the entity represented by builder.id."

[§buildDefinition.resolvedDependencies] "Unordered collection of artifacts needed at build time. Completeness is best effort, at least through SLSA Build L3."

[§runDetails.builder.id] "URI indicating the transitive closure of the trusted build platform. This is intended to be the sole determiner of the SLSA Build level."

[§runDetails.builder.version] "Map of names of components of the build platform to their version."

[§runDetails.metadata.invocationId] "Identifies this particular build invocation, which can be useful for finding associated logs or other ad-hoc analysis."

[§runDetails.metadata.startedOn] "The timestamp of when the build started."

[§runDetails.metadata.finishedOn] "The timestamp of when the build completed."

[§runDetails.byproducts] "Additional artifacts generated during the build that are not considered the 'output' of the build but might be needed during debugging or incident response."

SLSA Build Level 별 provenance 요구사항 (인용은 별도 supply-chain-slsa-provenance-framework.md)

요지: L1 = provenance exists (unsigned/incomplete 허용), L2 = signed provenance + hosted infrastructure, L3 = hardened/hermetic builder + tamper-resistant signing. ca-tmpl 현실 목표 = L2. L3 는 GitHub Actions hosted runner 만으로 도달 어렵다.

Claims Extracted / 추출된 주장

Claim ID Claim (이 자료가 직접 말하는 것) Evidence quote Strength Applies to Does not prove
SLSA-SCH-C1 in-toto Statement _type 은 항상 https://in-toto.io/Statement/v1 (고정 문자열) [§Statement — _type] "Identifier for the schema of the Statement. Always https://in-toto.io/Statement/v1 for this version." official-standard in-toto v1 Statement 사용 모든 attestation 다른 in-toto 버전 (v0.1 등) 의 _type 값을 보장하지 않음
SLSA-SCH-C2 Statement subject 의 각 element 는 digest 필드를 반드시 가져야 함 (MUST) [§Statement — subject] "Each element MUST have digest set." official-standard in-toto attestation subject 배열 digest 알고리즘 (sha256 vs sha512 등) 의 선택은 본 인용 범위 밖
SLSA-SCH-C3 SLSA v1.0 provenance 의 buildDefinition.externalParameters 는 외부 (user/tenant) 제어 파라미터; internalParametersbuilder.id 가 대표하는 entity 가 제어하는 파라미터 [§buildDefinition.externalParameters] "The parameters that are under external control, such as those set by a user or tenant of the build platform." + [§buildDefinition.internalParameters] "The parameters that are under the control of the entity represented by builder.id." official-standard SLSA v1.0 provenance 생성 external vs internal 의 경계 판단 책임이 누구에게 있는지는 spec 인용에 명시 없음
SLSA-SCH-C4 buildDefinition.resolvedDependencies 는 build 시점 필요 artifact 의 unordered collection; completeness 는 "best effort, at least through SLSA Build L3" [§buildDefinition.resolvedDependencies] "Unordered collection of artifacts needed at build time. Completeness is best effort, at least through SLSA Build L3." official-standard SLSA v1.0 provenance 의 dependency 캡처 L3 에서도 completeness 가 "guaranteed" 가 아닌 "best effort" — 누락 가능성 명시
SLSA-SCH-C5 runDetails.builder.id = trusted build platform 의 transitive closure 식별 URI; "sole determiner of the SLSA Build level" [§runDetails.builder.id] "URI indicating the transitive closure of the trusted build platform. This is intended to be the sole determiner of the SLSA Build level." official-standard SLSA Build level 평가 + slsa-verifier --builder-id 매칭 특정 URI 값이 어떤 Build level 에 해당하는지의 매핑 테이블은 본 인용에 없음
SLSA-SCH-C6 runDetails.metadata.invocationId 는 특정 build invocation 의 고유 식별자 (associated logs / ad-hoc analysis 용) [§runDetails.metadata.invocationId] "Identifies this particular build invocation, which can be useful for finding associated logs or other ad-hoc analysis." official-standard provenance 생성 시 invocation 추적 invocationId 의 정확한 형식 (UUID vs URI vs free string) 은 본 인용에 미지정
SLSA-SCH-C7 runDetails.byproducts 는 본 output 은 아니지만 build 중 생성된 부산물 (debugging / IR 용) [§runDetails.byproducts] "Additional artifacts generated during the build that are not considered the 'output' of the build but might be needed during debugging or incident response." official-standard provenance 의 byproduct 캡처 byproduct 가 attestation subject 에 포함되어야 한다는 뜻은 아님
SLSA-SCH-C8 predicateType 은 Predicate 타입 식별 URI; predicate 는 추가 파라미터 (unset = set-but-empty, predicateType 만으로 충분하면 생략 가능) [§Statement — predicateType] "URI identifying the type of the Predicate." + [§Statement — predicate] "Additional parameters of the Predicate. Unset is treated the same as set-but-empty. MAY be omitted if predicateType fully describes the predicate." official-standard in-toto Statement 의 predicate 사용 SLSA v1.0 provenance 의 predicateType 값 (https://slsa.dev/provenance/v1) 은 SLSA spec 측 정의

Strength 근거

모두 official-standard — SLSA 는 OpenSSF/Linux Foundation 의 industry consensus standard. in-toto Statement spec 은 CNCF in-toto project 의 v1 표준.

Usage Boundaries / 적용 경계

  • 이 자료가 직접 증명하는 것:
    • SLSA-SCH-C1 ~ C2: in-toto Statement 래퍼의 정확 필드명과 필수 제약
    • SLSA-SCH-C3 ~ C7: SLSA v1.0 provenance predicate 의 정확 필드명과 의미
    • SLSA-SCH-C8: Statement 의 predicateType / predicate 관계
  • 이 자료가 증명하지 않는 것:
    • SLSA v1.2 의 필드명 (v1.0 만 캡처. v1.2 마이그레이션 시 별도 raw 분리 캡처 예정)
    • slsa-verifier 의 정확한 검사 알고리즘 (별도 slsa-verifier repo 참조)
    • ca-tmpl 의 약식 필드명이 어떤 정확한 spec 필드로 매핑되는지의 "공식 매핑" — 본 자료는 spec 필드만 캡처, 매핑 책임은 ca-tmpl 구현 측
    • Cosign DSSE envelope signing 알고리즘 (별도 cosign-keyless-identity-verification-policy.md)
  • 내 프로젝트에 적용하려면 추가 확인이 필요한 것:
    • ca-tmpl provenance 생성기가 실제로 어떤 buildType URI 를 사용하는지 (GitHub Actions reusable workflow 의 표준 URI 채택 가능성)
    • runDetails.builder.id 에 어떤 URI 를 박을지 (예: https://github.com/actions/runner/github-hosted)
    • subject digest 가 Cosign 이 서명하는 artifact digest 와 정확히 일치하는지 검증 절차

slsa-verifier 검사 동작 요약 (외부 도구 거동 — Sigstore/SLSA repo 참조)

slsa-verifier (참조 구현) 는 다음을 검사한다 (slsa-verifier README 기반 요약, 본 자료의 직접 인용 아님):

  1. provenance DSSE envelope 의 cryptographic signature.
  2. --builder-idrunDetails.builder.id 매칭.
  3. --source-uri / --source-branch / --source-tagbuildDefinition.externalParameters (또는 builder 별 매핑된 위치) 매칭.

→ 약식 필드명 (build.config.source 등) 으로 생성된 provenance 는 verifier 가 위 필드를 찾지 못해 fail 한다. (이는 ca-tmpl 측 결론, 본 자료 직접 증명 X.)

메모 / Notes (내 프로젝트 해석)

본 섹션은 자료 직접 인용 아님. ca-tmpl 결정 컨텍스트 해석.

  • ca-tmpl provenance 생성기는 약식 필드 (build.config.source, build.invocation) 를 spec 필드 (buildDefinition.externalParameters, runDetails.metadata.invocationId) 로 정정해야 함. 약식 명명 forbidden.
  • subject[*].digest 는 알고리즘 키 (예: sha256) 와 hex string 으로 구성. Cosign 이 서명하는 artifact digest 와 일치해야 한다.
  • predicateType 문자열은 정확히 https://slsa.dev/provenance/v1 (trailing slash 없음).
  • v1.2 마이그레이션 시 필드 추가/변경이 있을 수 있어 별도 raw 로 분리 캡처 예정 (현재 본 문서는 v1.0 기준).