Pushgate.devDocs Open Pushgate.dev

Support matrix

What works where, generated from a machine-checked model of SLSA v1.2 and ALPS.

On this page

Pick where you build to see which SLSA and ALPS levels CI/lock reaches there today, which are tracked work, and which cannot be reached. A Supported result links to its setup guide. Every verdict is generated from a machine-checked model, not written by hand.

What works where

  • Supported works in released CI/lock today; links to its setup guide
  • Planned tracked work; links to its entry below
  • Not planned the model refutes it; the reason is shown
  • 1 holds under a named reading of the spec (see Notes)

GitHub Actions

GitHub-hosted runner (Linux or macOS) 3 supported 3 planned 6 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Source

  • L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

SLSA Build

ALPS

Source side. Evidence about the source repository, its history and its reviews.

SLSA Source

  • L1 Not plannedThe source host issues no Source VSA or source provenance.
  • L2 Not plannedThe source host issues no Source VSA or source provenance.
  • L3 Not plannedThe source host issues no Source VSA or source provenance.
  • L4 Not plannedThe source host issues no Source VSA or source provenance.

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

ALPS

GitHub-hosted runner, signing in a reusable workflow 3 supported 3 planned 6 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Source

  • L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

SLSA Build

ALPS

Source side. Evidence about the source repository, its history and its reviews.

SLSA Source

  • L1 Not plannedThe source host issues no Source VSA or source provenance.
  • L2 Not plannedThe source host issues no Source VSA or source provenance.
  • L3 Not plannedThe source host issues no Source VSA or source provenance.
  • L4 Not plannedThe source host issues no Source VSA or source provenance.

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

ALPS

GitHub self-hosted runner 3 supported 2 planned 7 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

SLSA Source

  • L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

SLSA Build

ALPS

Source side. Evidence about the source repository, its history and its reviews.

SLSA Source

  • L1 Not plannedThe source host issues no Source VSA or source provenance.
  • L2 Not plannedThe source host issues no Source VSA or source provenance.
  • L3 Not plannedThe source host issues no Source VSA or source provenance.
  • L4 Not plannedThe source host issues no Source VSA or source provenance.

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

SLSA Build

ALPS

cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.

SLSA Build

ALPS

GitHub-hosted runner (Windows) 3 supported 3 planned 2 not planned

The best result across CI/lock modes. The mode is named under each result.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

SLSA Build

ALPS

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

ALPS

cilockd (Windows). A signing daemon with a VBS-enclave key, outside the agent.

SLSA Build

ALPS

Other CI

GitLab.com hosted runners 2 supported 3 planned 7 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Source

  • L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

ALPS

Source side. Evidence about the source repository, its history and its reviews.

SLSA Source

  • L1 Not plannedThe source host issues no Source VSA or source provenance.
  • L2 Not plannedThe source host issues no Source VSA or source provenance.
  • L3 Not plannedThe source host issues no Source VSA or source provenance.
  • L4 Not plannedThe source host issues no Source VSA or source provenance.

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

SLSA Build

ALPS

GitLab self-managed 2 supported 3 planned 7 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Source

  • L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

ALPS

Source side. Evidence about the source repository, its history and its reviews.

SLSA Source

  • L1 Not plannedThe source host issues no Source VSA or source provenance.
  • L2 Not plannedThe source host issues no Source VSA or source provenance.
  • L3 Not plannedThe source host issues no Source VSA or source provenance.
  • L4 Not plannedThe source host issues no Source VSA or source provenance.

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

SLSA Build

ALPS

  • 0 PlannedIsolated provenance workflow
  • 1 Not plannedThe build has no workload identity the platform can certify.
  • 2 Not plannedThe build has no workload identity the platform can certify.
  • 3 Not plannedThe build has no workload identity the platform can certify.

cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.

SLSA Build

ALPS

  • 0 Plannedcilockd on Linux
  • 1 Not plannedThe build has no workload identity the platform can certify.
  • 2 Not plannedThe build has no workload identity the platform can certify.
  • 3 Not plannedThe build has no workload identity the platform can certify.
Buildkite hosted agents 2 supported 3 planned 3 not planned

The best result across CI/lock modes. The mode is named under each result.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

ALPS

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

SLSA Build

ALPS

CircleCI cloud 2 supported 3 planned 3 not planned

The best result across CI/lock modes. The mode is named under each result.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

ALPS

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

SLSA Build

ALPS

Jenkins 2 supported 3 planned 3 not planned

The best result across CI/lock modes. The mode is named under each result.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

ALPS

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

SLSA Build

ALPS

  • 0 PlannedIsolated provenance workflow
  • 1 Not plannedThe build has no workload identity the platform can certify.
  • 2 Not plannedThe build has no workload identity the platform can certify.
  • 3 Not plannedThe build has no workload identity the platform can certify.

cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.

SLSA Build

ALPS

  • 0 Plannedcilockd on Linux
  • 1 Not plannedThe build has no workload identity the platform can certify.
  • 2 Not plannedThe build has no workload identity the platform can certify.
  • 3 Not plannedThe build has no workload identity the platform can certify.
Azure DevOps Microsoft-hosted agents 2 supported 3 planned 3 not planned

The best result across CI/lock modes. The mode is named under each result.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

ALPS

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

SLSA Build

ALPS

  • 0 PlannedIsolated provenance workflow
  • 1 Not plannedThe build has no workload identity the platform can certify.
  • 2 Not plannedThe build has no workload identity the platform can certify.
  • 3 Not plannedThe build has no workload identity the platform can certify.
AWS CodeBuild (on-demand) 2 supported 1 planned 5 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

SLSA Build

ALPS

  • 0 SupportedSetup guide: Any CI with a signing key
  • 1 Not plannedThe build has no workload identity the platform can certify.
  • 2 Not plannedThe build has no workload identity the platform can certify.
  • 3 Not plannedThe build has no workload identity the platform can certify.

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

SLSA Build

ALPS

  • 0 PlannedIsolated provenance workflow
  • 1 Not plannedThe build has no workload identity the platform can certify.
  • 2 Not plannedThe build has no workload identity the platform can certify.
  • 3 Not plannedThe build has no workload identity the platform can certify.
Google Cloud Build 2 supported 3 planned 3 not planned

The best result across CI/lock modes. The mode is named under each result.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

ALPS

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

SLSA Build

ALPS

  • 0 PlannedIsolated provenance workflow
  • 1 Not plannedThe build has no workload identity the platform can certify.
  • 2 Not plannedThe build has no workload identity the platform can certify.
  • 3 Not plannedThe build has no workload identity the platform can certify.

Kubernetes

Kubernetes pod (EKS, GKE or AKS) 2 supported 3 planned 3 not planned

The best result across CI/lock modes. The mode is named under each result.

ALPS

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

ALPS

Separate signer. A separate job, which the build steps cannot reach, signs the provenance.

SLSA Build

ALPS

  • 0 PlannedIsolated provenance workflow
  • 1 Not plannedThe build has no workload identity the platform can certify.
  • 2 Not plannedThe build has no workload identity the platform can certify.
  • 3 Not plannedThe build has no workload identity the platform can certify.
Kubernetes pod with a cilockd sidecar 0 supported 5 planned 3 not planned

The best result across CI/lock modes. The mode is named under each result.

ALPS

  • 0 Plannedcilockd (Linux)cilockd on Linux
  • 1 Not plannedcilockd (Linux)The build has no workload identity the platform can certify.
  • 2 Not plannedcilockd (Linux)The build has no workload identity the platform can certify.
  • 3 Not plannedcilockd (Linux)The build has no workload identity the platform can certify.
Results by CI/lock mode

cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.

ALPS

  • 0 Plannedcilockd on Linux
  • 1 Not plannedThe build has no workload identity the platform can certify.
  • 2 Not plannedThe build has no workload identity the platform can certify.
  • 3 Not plannedThe build has no workload identity the platform can certify.

Developer machines and agents

Pushgate (an agent pushes from a workstation) 3 supported 2 planned 7 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

SLSA Source

  • L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
  • L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.
Results by CI/lock mode

Pushgate mint. CI/lock signs on the developer machine; Pushgate verifies the evidence at git push.

SLSA Build

Source side. Evidence about the source repository, its history and its reviews.

SLSA Source

  • L1 Not plannedThe source host issues no Source VSA or source provenance.
  • L2 Not plannedThe source host issues no Source VSA or source provenance.
  • L3 Not plannedThe source host issues no Source VSA or source provenance.
  • L4 Not plannedThe source host issues no Source VSA or source provenance.

cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.

SLSA Build

ALPS

Developer workstation (macOS or Linux) 3 supported 2 planned 3 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

SLSA Build

cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.

SLSA Build

ALPS

Linux workstation with a TPM 3 supported 3 planned 2 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

Results by CI/lock mode

Inline. CI/lock runs and signs inside the build job or agent session.

SLSA Build

cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.

SLSA Build

macOS with cilockd

macOS 27, Apple silicon, MDM-managed 0 supported 6 planned 2 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

Results by CI/lock mode

cilockd (macOS). A signing daemon with an App Attest key, outside the agent.

SLSA Build

macOS 27, Apple silicon, unmanaged 0 supported 6 planned 2 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

Results by CI/lock mode

cilockd (macOS). A signing daemon with an App Attest key, outside the agent.

SLSA Build

Intel Mac 0 supported 5 planned 3 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

ALPS

Results by CI/lock mode

cilockd (macOS). A signing daemon with an App Attest key, outside the agent.

SLSA Build

ALPS

Windows with cilockd

Windows 11, TPM and Secure Boot, Intune-managed 0 supported 6 planned 2 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

Results by CI/lock mode

cilockd (Windows). A signing daemon with a VBS-enclave key, outside the agent.

SLSA Build

Windows 11, TPM and Secure Boot, unmanaged 0 supported 6 planned 2 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

Results by CI/lock mode

cilockd (Windows). A signing daemon with a VBS-enclave key, outside the agent.

SLSA Build

Windows Server 2025 on Azure Trusted Launch (self-hosted runner) 0 supported 7 planned 1 not planned
Results by CI/lock mode

cilockd (Windows). A signing daemon with a VBS-enclave key, outside the agent.

SLSA Build

Windows without a TPM, or with Secure Boot off 0 supported 5 planned 3 not planned

The best result across CI/lock modes. The mode is named under each result.

SLSA Build

Results by CI/lock mode

cilockd (Windows). A signing daemon with a VBS-enclave key, outside the agent.

SLSA Build

ALPS

Source repositories

GitHub repository that only Pushgate can push to 0 supported 4 planned 0 not planned
Results by CI/lock mode

Pushgate Source VSA. Pushgate signs a SLSA Source verification summary for each push it admits.

GitHub repository that also accepts direct pushes 0 supported 4 planned 0 not planned
Results by CI/lock mode

Pushgate Source VSA. Pushgate signs a SLSA Source verification summary for each push it admits.

Full matrix: every environment, best result
EnvironmentSLSA BuildSLSA SourceALPS
SLSA Build L0SLSA Build L1SLSA Build L2SLSA Build L3SLSA Source L1SLSA Source L2SLSA Source L3SLSA Source L4ALPS 0ALPS 1ALPS 2ALPS 3
GitHub Actions
GitHub-hosted runner (Linux or macOS)
GitHub-hosted runner, signing in a reusable workflow
GitHub self-hosted runner
GitHub-hosted runner (Windows)not evaluatednot evaluatednot evaluatednot evaluated
Other CI
GitLab.com hosted runners
GitLab self-managed
Buildkite hosted agentsnot evaluatednot evaluatednot evaluatednot evaluated
CircleCI cloudnot evaluatednot evaluatednot evaluatednot evaluated
Jenkinsnot evaluatednot evaluatednot evaluatednot evaluated
Azure DevOps Microsoft-hosted agentsnot evaluatednot evaluatednot evaluatednot evaluated
AWS CodeBuild (on-demand)not evaluatednot evaluatednot evaluatednot evaluated
Google Cloud Buildnot evaluatednot evaluatednot evaluatednot evaluated
Kubernetes
Kubernetes pod (EKS, GKE or AKS)not evaluatednot evaluatednot evaluatednot evaluated
Kubernetes pod with a cilockd sidecarnot evaluatednot evaluatednot evaluatednot evaluated
Developer machines and agents
Pushgate (an agent pushes from a workstation)
Developer workstation (macOS or Linux)not evaluatednot evaluatednot evaluatednot evaluated
Linux workstation with a TPMnot evaluatednot evaluatednot evaluatednot evaluated
macOS with cilockd
macOS 27, Apple silicon, MDM-managednot evaluatednot evaluatednot evaluatednot evaluated
macOS 27, Apple silicon, unmanagednot evaluatednot evaluatednot evaluatednot evaluated
Intel Macnot evaluatednot evaluatednot evaluatednot evaluated
Windows with cilockd
Windows 11, TPM and Secure Boot, Intune-managednot evaluatednot evaluatednot evaluatednot evaluated
Windows 11, TPM and Secure Boot, unmanagednot evaluatednot evaluatednot evaluatednot evaluated
Windows Server 2025 on Azure Trusted Launch (self-hosted runner)not evaluatednot evaluatednot evaluatednot evaluated
Windows without a TPM, or with Secure Boot offnot evaluatednot evaluatednot evaluatednot evaluated
Source repositories
GitHub repository that only Pushgate can push tonot evaluatednot evaluatednot evaluatednot evaluatednot evaluatednot evaluatednot evaluatednot evaluated
GitHub repository that also accepts direct pushesnot evaluatednot evaluatednot evaluatednot evaluatednot evaluatednot evaluatednot evaluatednot evaluated

Planned work

Isolated provenance workflow
A reusable GitHub workflow signs the provenance in a job the build steps cannot reach. It is the separate-signer mode, and the path to SLSA Build L3 on GitHub Actions. The workflow and the L3 verifier are not merged yet, and the provenance format fix is open. Tracking: testifysec/judge#9822, testifysec/judge#9827.
ALPS 2 boundary attestation
A trusted observer outside the agent records the sandbox that was applied, so a verifier can check it. Designed, not built. Tracking: testifysec/judge#8314.
cilockd on Linux
A signing daemon outside the build or agent, with a TPM-held key and a measured daemon identity. Tracking: testifysec/judge#9844, testifysec/judge#9845.
cilockd on macOS
A signing daemon whose key is attested by Apple App Attest, through a helper app the agent cannot drive. Tracking: testifysec/judge#9844, testifysec/judge#9846.
cilockd on Windows
A signing daemon whose key lives in a VBS enclave, with a TPM quote of the boot state. Tracking: testifysec/judge#9844, testifysec/judge#9847.
Platform keyless signing beyond GitHub Actions
The platform certificate authority accepts GitHub Actions, GitLab.com, Buildkite and CircleCI workload identities (#9839). No guide documents platform keyless signing on GitLab.com, Buildkite or CircleCI yet, so ALPS 1 there is listed as planned until one does. Tracking: testifysec/judge#9839.
SLSA v1 provenance type
CI/lock's slsa attestor emits predicateType https://slsa.dev/provenance/v1.0, which SLSA verifiers do not recognize. SLSA Build L1 and above are listed as planned until it emits https://slsa.dev/provenance/v1. Tracking: testifysec/judge#9827.
Pushgate Source VSA
Pushgate verifies every push it gates but does not yet issue a SLSA Source VSA for it. Designed, not built. Tracking: testifysec/judge#9931.

Not shown: the draft SLSA Build Environment and Dependency tracks. The Source track is evaluated only where CI/lock collects source-side evidence.

Generated from formal/slsa-tracks/matrix.json (sha256 be858e073977), a Lean 4 model of SLSA v1.2 (Build, Source) + working draft (BuildEnv, Dependency); ALPS 0.1. Each cell is a theorem. Supported cells were checked against shipped code on main at cbc65c7e41 on 2026-09-25.

Why the mode matters

ALPS 3 isolated signing service A coding-agent client sends a typed proof request to a separate CI/lock service. The service independently validates repository, commit, command, predicate, output, expiry, and replay bounds before using hardware-backed non-exportable identity and platform keyless signing. It never exposes a generic signing oracle. AGENT SANDBOX CLIENTCI/lock request typed only ISOLATED SERVICE INDEPENDENT VALIDATIONRepo · commit · command · output signed / measured binary · no generic signer HARDWARE + PLATFORM NON-EXPORTABLETPM · HSM · Secure Enclave Fulcio leaf + mandatory RFC 3161
The highest levels need a signer the build steps or the agent cannot reach. SLSA Build L3 and ALPS 3 wait on one, which is why the mode sits beside every result.
Mermaid source
flowchart LR
    A[Agent sandbox] -->|typed proof request| D[CI/lock service]
    D -->|validate repo + commit + command + output| H[Non-exportable hardware identity]
    H -->|keyless leaf + RFC 3161| P[TestifySec platform]
    P --> E[Signed evidence]
    G[No generic signing oracle] -.-> D

In the inline mode, CI/lock signs inside the job or agent session it observes, so code in that job can use the same signing identity. That is enough for ALPS 1, and for SLSA Build L2 once cilock emits the SLSA v1 provenance type (it emits v1.0 today; that fix is tracked above), and it is why no inline cell reaches Build L3 or ALPS 3. The separate-signer and cilockd modes move the signer out of reach, and they are the tracked work listed above.