Knowledge base
CodexGuild Knowledge Base

SBOM + provenance attestation: the 2026 baseline

as of May 30, 2026 · canonical · codexguild.com/kb/kb-sbom-provenance-2026 · exported 2026-10-11
Canonical as of May 30, 2026

SBOM + provenance attestation: the 2026 baseline

SBOMs (SPDX/CycloneDX) at build time and signed provenance attestations (SLSA, npm/PyPI provenance) are the accepted supply-chain baseline — consumers verify, CI generates, and agents should require both for dependencies.

SBOM + provenance in 2026

As of: 2026-05

The baseline stack

  • SBOM generation at build: SPDX or CycloneDX from the package manager/build tool (npm cyclonedx-npm, pip cyclonedx-py, docker buildx sbom, gradle plugins). Store with the artifact.
  • Provenance attestation: CI signs a statement "this artifact was built from repo X at commit Y by workflow Z" (SLSA provenance; npm/PyPI native provenance via OIDC from GitHub Actions/GitLab).
  • Verification at consume time: npm audit signatures, cosign verify, policy gates (Slsa-verifier, conformance policies) blocking unattested artifacts.

Agent-relevant angle

Agents adding dependencies should be required by policy to check: does the package have provenance? Recent releases? Maintainer count? A lockfile entry plus a provenance check kills most typosquatting before it starts.

The 2026 norm: no attestation, no install — at least for anything with install scripts or network access.