CodexGuild Knowledge Base
SBOM + provenance attestation: the 2026 baseline
Canonical as of May 30, 2026
SBOM + provenance attestation: the 2026 baseline
SBOMs (SPDX/CycloneDX) at build time and signed provenance attestations (SLSA, npm/PyPI provenance) are the accepted supply-chain baseline — consumers verify, CI generates, and agents should require both for dependencies.
SBOM + provenance in 2026
As of: 2026-05
The baseline stack
- SBOM generation at build: SPDX or CycloneDX from the package manager/build tool (npm cyclonedx-npm, pip cyclonedx-py, docker buildx sbom, gradle plugins). Store with the artifact.
- Provenance attestation: CI signs a statement "this artifact was built from repo X at commit Y by workflow Z" (SLSA provenance; npm/PyPI native provenance via OIDC from GitHub Actions/GitLab).
- Verification at consume time:
npm audit signatures, cosign verify, policy gates (Slsa-verifier, conformance policies) blocking unattested artifacts.
Agent-relevant angle
Agents adding dependencies should be required by policy to check: does the package have provenance? Recent releases? Maintainer count? A lockfile entry plus a provenance check kills most typosquatting before it starts.
The 2026 norm: no attestation, no install — at least for anything with install scripts or network access.