Support matrix
What works where, generated from a machine-checked model of SLSA v1.2 and ALPS.
On this page
Pick where you build to see which SLSA and ALPS levels CI/lock reaches there today, which are tracked work, and which cannot be reached. A Supported result links to its setup guide. Every verdict is generated from a machine-checked model, not written by hand.
What works where
- Supported works in released CI/lock today; links to its setup guide
- Planned tracked work; links to its entry below
- Not planned the model refutes it; the reason is shown
- 1 holds under a named reading of the spec (see Notes)
GitHub Actions
GitHub-hosted runner (Linux or macOS) 3 supported 3 planned 6 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
SLSA Source
- L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.
ALPS
- 0 SupportedInlineSetup guide: GitHub Actions
- 1 SupportedInlineSetup guide: GitHub Actions
- 2 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: GitHub Actions
- L1 PlannedSLSA v1 provenance type
- L2 PlannedSLSA v1 provenance type
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 SupportedSetup guide: GitHub Actions
- 1 SupportedSetup guide: GitHub Actions
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
Source side. Evidence about the source repository, its history and its reviews.
SLSA Source
- L1 Not plannedThe source host issues no Source VSA or source provenance.
- L2 Not plannedThe source host issues no Source VSA or source provenance.
- L3 Not plannedThe source host issues no Source VSA or source provenance.
- L4 Not plannedThe source host issues no Source VSA or source provenance.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
ALPS
- 0 PlannedIsolated provenance workflow
- 1 PlannedIsolated provenance workflow
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
GitHub-hosted runner, signing in a reusable workflow 3 supported 3 planned 6 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
SLSA Source
- L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.
ALPS
- 0 SupportedInlineSetup guide: GitHub Actions
- 1 SupportedInlineSetup guide: GitHub Actions
- 2 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: GitHub Actions
- L1 PlannedSLSA v1 provenance type
- L2 PlannedSLSA v1 provenance type
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 SupportedSetup guide: GitHub Actions
- 1 SupportedSetup guide: GitHub Actions
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
Source side. Evidence about the source repository, its history and its reviews.
SLSA Source
- L1 Not plannedThe source host issues no Source VSA or source provenance.
- L2 Not plannedThe source host issues no Source VSA or source provenance.
- L3 Not plannedThe source host issues no Source VSA or source provenance.
- L4 Not plannedThe source host issues no Source VSA or source provenance.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
ALPS
- 0 PlannedIsolated provenance workflow
- 1 PlannedIsolated provenance workflow
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
GitHub self-hosted runner 3 supported 2 planned 7 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: GitHub Actions
- L1 PlannedInlineSLSA v1 provenance type
- L2 PlannedInlineSLSA v1 provenance type
- L3 Not plannedInlineThe worker is reused between jobs, so builds are not isolated.
SLSA Source
- L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.
ALPS
- 0 SupportedInlineSetup guide: GitHub Actions
- 1 SupportedInlineSetup guide: GitHub Actions
- 2 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: GitHub Actions
- L1 PlannedSLSA v1 provenance type
- L2 PlannedSLSA v1 provenance type
- L3 Not plannedThe worker is reused between jobs, so builds are not isolated.
ALPS
- 0 SupportedSetup guide: GitHub Actions
- 1 SupportedSetup guide: GitHub Actions
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
Source side. Evidence about the source repository, its history and its reviews.
SLSA Source
- L1 Not plannedThe source host issues no Source VSA or source provenance.
- L2 Not plannedThe source host issues no Source VSA or source provenance.
- L3 Not plannedThe source host issues no Source VSA or source provenance.
- L4 Not plannedThe source host issues no Source VSA or source provenance.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
- L0 PlannedIsolated provenance workflow
- L1 PlannedIsolated provenance workflow
- L2 PlannedIsolated provenance workflow
- L3 Not plannedThe worker is reused between jobs, so builds are not isolated.
ALPS
- 0 PlannedIsolated provenance workflow
- 1 PlannedIsolated provenance workflow
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.
SLSA Build
- L0 Plannedcilockd on Linux
- L1 Plannedcilockd on Linux
- L2 Not plannedA tenant step, not the build platform, generates the provenance.
- L3 Not plannedA tenant step, not the build platform, generates the provenance.
ALPS
- 0 Plannedcilockd on Linux
- 1 Plannedcilockd on Linux
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
GitHub-hosted runner (Windows) 3 supported 3 planned 2 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
ALPS
- 0 SupportedInlineSetup guide: GitHub-hosted Windows runners
- 1 SupportedInlineSetup guide: GitHub-hosted Windows runners
- 2 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: GitHub-hosted Windows runners
- L1 PlannedSLSA v1 provenance type
- L2 PlannedSLSA v1 provenance type
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 SupportedSetup guide: GitHub-hosted Windows runners
- 1 SupportedSetup guide: GitHub-hosted Windows runners
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
ALPS
- 0 PlannedIsolated provenance workflow
- 1 PlannedIsolated provenance workflow
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
cilockd (Windows). A signing daemon with a VBS-enclave key, outside the agent.
SLSA Build
- L0 Plannedcilockd on Windows
- L1 Plannedcilockd on Windows
- L2 Not plannedA tenant step, not the build platform, generates the provenance.
- L3 Not plannedA tenant step, not the build platform, generates the provenance.
ALPS
- 0 Plannedcilockd on Windows
- 1 Plannedcilockd on Windows
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
Other CI
GitLab.com hosted runners 2 supported 3 planned 7 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- L1 PlannedInlineSLSA v1 provenance type
- L2 PlannedInlineSLSA v1 provenance type
- L3 Not plannedInlineBuild steps can use the signing identity, so they can forge the provenance.
SLSA Source
- L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.
ALPS
- 0 SupportedInlineSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- 1 PlannedInlinePlatform keyless signing beyond GitHub Actions
- 2 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- L1 PlannedSLSA v1 provenance type
- L2 PlannedSLSA v1 provenance type
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 SupportedSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- 1 PlannedPlatform keyless signing beyond GitHub Actions
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
Source side. Evidence about the source repository, its history and its reviews.
SLSA Source
- L1 Not plannedThe source host issues no Source VSA or source provenance.
- L2 Not plannedThe source host issues no Source VSA or source provenance.
- L3 Not plannedThe source host issues no Source VSA or source provenance.
- L4 Not plannedThe source host issues no Source VSA or source provenance.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
- L0 PlannedIsolated provenance workflow
- L1 PlannedIsolated provenance workflow
- L2 PlannedIsolated provenance workflow
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 PlannedIsolated provenance workflow
- 1 PlannedIsolated provenance workflow
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
GitLab self-managed 2 supported 3 planned 7 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: Any CI with a signing key
- L1 PlannedInlineSLSA v1 provenance type
- L2 PlannedInlinePlatform keyless signing beyond GitHub Actions
- L3 Not plannedInlineNo certificate authority accepts this build's identity.
SLSA Source
- L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.
ALPS
- 0 SupportedInlineSetup guide: Any CI with a signing key
- 1 PlannedInlinePlatform keyless signing beyond GitHub Actions
- 2 Not plannedInlineThe build has no workload identity the platform can certify.
- 3 Not plannedInlineThe build has no workload identity the platform can certify.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: Any CI with a signing key
- L1 PlannedSLSA v1 provenance type
- L2 PlannedPlatform keyless signing beyond GitHub Actions
- L3 Not plannedNo certificate authority accepts this build's identity.
ALPS
- 0 SupportedSetup guide: Any CI with a signing key
- 1 PlannedPlatform keyless signing beyond GitHub Actions
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Source side. Evidence about the source repository, its history and its reviews.
SLSA Source
- L1 Not plannedThe source host issues no Source VSA or source provenance.
- L2 Not plannedThe source host issues no Source VSA or source provenance.
- L3 Not plannedThe source host issues no Source VSA or source provenance.
- L4 Not plannedThe source host issues no Source VSA or source provenance.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
- L0 PlannedIsolated provenance workflow
- L1 PlannedIsolated provenance workflow
- L2 Not plannedNo certificate authority accepts this build's identity.
- L3 Not plannedNo certificate authority accepts this build's identity.
ALPS
- 0 PlannedIsolated provenance workflow
- 1 Not plannedThe build has no workload identity the platform can certify.
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.
SLSA Build
- L0 Plannedcilockd on Linux
- L1 Plannedcilockd on Linux
- L2 Not plannedNo certificate authority accepts this build's identity.
- L3 Not plannedNo certificate authority accepts this build's identity.
ALPS
- 0 Plannedcilockd on Linux
- 1 Not plannedThe build has no workload identity the platform can certify.
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Buildkite hosted agents 2 supported 3 planned 3 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- L1 PlannedInlineSLSA v1 provenance type
- L2 PlannedInlineSLSA v1 provenance type
- L3 Not plannedInlineBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 SupportedInlineSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- 1 PlannedInlinePlatform keyless signing beyond GitHub Actions
- 2 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- L1 PlannedSLSA v1 provenance type
- L2 PlannedSLSA v1 provenance type
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 SupportedSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- 1 PlannedPlatform keyless signing beyond GitHub Actions
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
- L0 PlannedIsolated provenance workflow
- L1 PlannedIsolated provenance workflow
- L2 PlannedIsolated provenance workflow
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 PlannedIsolated provenance workflow
- 1 PlannedIsolated provenance workflow
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
CircleCI cloud 2 supported 3 planned 3 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- L1 PlannedInlineSLSA v1 provenance type
- L2 PlannedInlineSLSA v1 provenance type
- L3 Not plannedInlineBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 SupportedInlineSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- 1 PlannedInlinePlatform keyless signing beyond GitHub Actions
- 2 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedInlineSteps run with root on this worker, so no sandbox can contain the agent.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- L1 PlannedSLSA v1 provenance type
- L2 PlannedSLSA v1 provenance type
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 SupportedSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- 1 PlannedPlatform keyless signing beyond GitHub Actions
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
- L0 PlannedIsolated provenance workflow
- L1 PlannedIsolated provenance workflow
- L2 PlannedIsolated provenance workflow
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 PlannedIsolated provenance workflow
- 1 PlannedIsolated provenance workflow
- 2 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
- 3 Not plannedSteps run with root on this worker, so no sandbox can contain the agent.
Jenkins 2 supported 3 planned 3 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: Any CI with a signing key
- L1 PlannedInlineSLSA v1 provenance type
- L2 PlannedInlinePlatform keyless signing beyond GitHub Actions
- L3 Not plannedInlineNo certificate authority accepts this build's identity.
ALPS
- 0 SupportedInlineSetup guide: Any CI with a signing key
- 1 PlannedInlinePlatform keyless signing beyond GitHub Actions
- 2 Not plannedInlineThe build has no workload identity the platform can certify.
- 3 Not plannedInlineThe build has no workload identity the platform can certify.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: Any CI with a signing key
- L1 PlannedSLSA v1 provenance type
- L2 PlannedPlatform keyless signing beyond GitHub Actions
- L3 Not plannedNo certificate authority accepts this build's identity.
ALPS
- 0 SupportedSetup guide: Any CI with a signing key
- 1 PlannedPlatform keyless signing beyond GitHub Actions
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
- L0 PlannedIsolated provenance workflow
- L1 PlannedIsolated provenance workflow
- L2 Not plannedNo certificate authority accepts this build's identity.
- L3 Not plannedNo certificate authority accepts this build's identity.
ALPS
- 0 PlannedIsolated provenance workflow
- 1 Not plannedThe build has no workload identity the platform can certify.
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.
SLSA Build
- L0 Plannedcilockd on Linux
- L1 Plannedcilockd on Linux
- L2 Not plannedNo certificate authority accepts this build's identity.
- L3 Not plannedNo certificate authority accepts this build's identity.
ALPS
- 0 Plannedcilockd on Linux
- 1 Not plannedThe build has no workload identity the platform can certify.
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Azure DevOps Microsoft-hosted agents 2 supported 3 planned 3 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: Any CI with a signing key
- L1 PlannedInlineSLSA v1 provenance type
- L2 PlannedInlinePlatform keyless signing beyond GitHub Actions
- L3 Not plannedInlineNo certificate authority accepts this build's identity.
ALPS
- 0 SupportedInlineSetup guide: Any CI with a signing key
- 1 PlannedInlinePlatform keyless signing beyond GitHub Actions
- 2 Not plannedInlineThe build has no workload identity the platform can certify.
- 3 Not plannedInlineThe build has no workload identity the platform can certify.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: Any CI with a signing key
- L1 PlannedSLSA v1 provenance type
- L2 PlannedPlatform keyless signing beyond GitHub Actions
- L3 Not plannedNo certificate authority accepts this build's identity.
ALPS
- 0 SupportedSetup guide: Any CI with a signing key
- 1 PlannedPlatform keyless signing beyond GitHub Actions
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
- L0 PlannedIsolated provenance workflow
- L1 PlannedIsolated provenance workflow
- L2 Not plannedNo certificate authority accepts this build's identity.
- L3 Not plannedNo certificate authority accepts this build's identity.
ALPS
- 0 PlannedIsolated provenance workflow
- 1 Not plannedThe build has no workload identity the platform can certify.
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
AWS CodeBuild (on-demand) 2 supported 1 planned 5 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: Any CI with a signing key
- L1 PlannedInlineSLSA v1 provenance type
- L2 Not plannedInlineThe build has no workload identity token to sign with.
- L3 Not plannedInlineThe build has no workload identity token to sign with.
ALPS
- 0 SupportedInlineSetup guide: Any CI with a signing key
- 1 Not plannedInlineThe build has no workload identity the platform can certify.
- 2 Not plannedInlineThe build has no workload identity the platform can certify.
- 3 Not plannedInlineThe build has no workload identity the platform can certify.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: Any CI with a signing key
- L1 PlannedSLSA v1 provenance type
- L2 Not plannedThe build has no workload identity token to sign with.
- L3 Not plannedThe build has no workload identity token to sign with.
ALPS
- 0 SupportedSetup guide: Any CI with a signing key
- 1 Not plannedThe build has no workload identity the platform can certify.
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
- L0 PlannedIsolated provenance workflow
- L1 PlannedIsolated provenance workflow
- L2 Not plannedThe build has no workload identity token to sign with.
- L3 Not plannedThe build has no workload identity token to sign with.
ALPS
- 0 PlannedIsolated provenance workflow
- 1 Not plannedThe build has no workload identity the platform can certify.
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Google Cloud Build 2 supported 3 planned 3 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: Any CI with a signing key
- L1 PlannedInlineSLSA v1 provenance type
- L2 PlannedInlinePlatform keyless signing beyond GitHub Actions
- L3 Not plannedInlineNo certificate authority accepts this build's identity.
ALPS
- 0 SupportedInlineSetup guide: Any CI with a signing key
- 1 PlannedInlinePlatform keyless signing beyond GitHub Actions
- 2 Not plannedInlineThe build has no workload identity the platform can certify.
- 3 Not plannedInlineThe build has no workload identity the platform can certify.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: Any CI with a signing key
- L1 PlannedSLSA v1 provenance type
- L2 PlannedPlatform keyless signing beyond GitHub Actions
- L3 Not plannedNo certificate authority accepts this build's identity.
ALPS
- 0 SupportedSetup guide: Any CI with a signing key
- 1 PlannedPlatform keyless signing beyond GitHub Actions
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
- L0 PlannedIsolated provenance workflow
- L1 PlannedIsolated provenance workflow
- L2 Not plannedNo certificate authority accepts this build's identity.
- L3 Not plannedNo certificate authority accepts this build's identity.
ALPS
- 0 PlannedIsolated provenance workflow
- 1 Not plannedThe build has no workload identity the platform can certify.
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Kubernetes
Kubernetes pod (EKS, GKE or AKS) 2 supported 3 planned 3 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- L1 PlannedInlineSLSA v1 provenance type
- L2 PlannedInlineSLSA v1 provenance type
- L3 Not plannedInlineBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 SupportedInlineSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- 1 PlannedInlinePlatform keyless signing beyond GitHub Actions
- 2 Not plannedInlineThe build has no workload identity the platform can certify.
- 3 Not plannedInlineThe build has no workload identity the platform can certify.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- L1 PlannedSLSA v1 provenance type
- L2 PlannedSLSA v1 provenance type
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 SupportedSetup guide: GitLab.com, Buildkite, CircleCI and Kubernetes with public Sigstore
- 1 PlannedPlatform keyless signing beyond GitHub Actions
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Separate signer. A separate job, which the build steps cannot reach, signs the provenance.
SLSA Build
- L0 PlannedIsolated provenance workflow
- L1 PlannedIsolated provenance workflow
- L2 PlannedIsolated provenance workflow
- L3 Not plannedBuild steps can use the signing identity, so they can forge the provenance.
ALPS
- 0 PlannedIsolated provenance workflow
- 1 Not plannedThe build has no workload identity the platform can certify.
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Kubernetes pod with a cilockd sidecar 0 supported 5 planned 3 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
ALPS
- 0 Plannedcilockd (Linux)cilockd on Linux
- 1 Not plannedcilockd (Linux)The build has no workload identity the platform can certify.
- 2 Not plannedcilockd (Linux)The build has no workload identity the platform can certify.
- 3 Not plannedcilockd (Linux)The build has no workload identity the platform can certify.
Results by CI/lock mode
cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.
SLSA Build
ALPS
- 0 Plannedcilockd on Linux
- 1 Not plannedThe build has no workload identity the platform can certify.
- 2 Not plannedThe build has no workload identity the platform can certify.
- 3 Not plannedThe build has no workload identity the platform can certify.
Developer machines and agents
Pushgate (an agent pushes from a workstation) 3 supported 2 planned 7 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedPushgate mintSetup guide: Pushgate first signed push
- L1 PlannedPushgate mintSLSA v1 provenance type
- L2 Not plannedPushgate mintA personal workstation is not a hosted build platform.
- L3 Not plannedPushgate mintA personal workstation is not a hosted build platform.
SLSA Source
- L1 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L2 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L3 Not plannedSource sideThe source host issues no Source VSA or source provenance.
- L4 Not plannedSource sideThe source host issues no Source VSA or source provenance.
ALPS
- 0 SupportedPushgate mintSetup guide: Pushgate first signed push
- 1 SupportedPushgate mintSetup guide: Pushgate first signed push
- 2 PlannedPushgate mintALPS 2 boundary attestation
- 3 Not plannedPushgate mintNeeds the cilockd signing daemon, which this mode does not run.
Results by CI/lock mode
Pushgate mint. CI/lock signs on the developer machine; Pushgate verifies the evidence at git push.
SLSA Build
- L0 SupportedSetup guide: Pushgate first signed push
- L1 PlannedSLSA v1 provenance type
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
ALPS
- 0 SupportedSetup guide: Pushgate first signed push
- 1 SupportedSetup guide: Pushgate first signed push
- 2 PlannedALPS 2 boundary attestation
- 3 Not plannedNeeds the cilockd signing daemon, which this mode does not run.
Source side. Evidence about the source repository, its history and its reviews.
SLSA Source
- L1 Not plannedThe source host issues no Source VSA or source provenance.
- L2 Not plannedThe source host issues no Source VSA or source provenance.
- L3 Not plannedThe source host issues no Source VSA or source provenance.
- L4 Not plannedThe source host issues no Source VSA or source provenance.
cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.
SLSA Build
- L0 Plannedcilockd on Linux
- L1 Plannedcilockd on Linux
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
ALPS
- 0 Plannedcilockd on Linux
- 1 Plannedcilockd on Linux
- 2 Plannedcilockd on Linux
- 3 Not plannedThe machine offers no hardware-attested signing key.
Developer workstation (macOS or Linux) 3 supported 2 planned 3 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: An enrolled agent on a workstation
- L1 PlannedInlineSLSA v1 provenance type
- L2 Not plannedInlineA personal workstation is not a hosted build platform.
- L3 Not plannedInlineA personal workstation is not a hosted build platform.
ALPS
- 0 SupportedInlineSetup guide: An enrolled agent on a workstation
- 1 SupportedInlineSetup guide: An enrolled agent on a workstation
- 2 PlannedInlineALPS 2 boundary attestation
- 3 Not plannedInlineNeeds the cilockd signing daemon, which this mode does not run.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: An enrolled agent on a workstation
- L1 PlannedSLSA v1 provenance type
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
ALPS
- 0 SupportedSetup guide: An enrolled agent on a workstation
- 1 SupportedSetup guide: An enrolled agent on a workstation
- 2 PlannedALPS 2 boundary attestation
- 3 Not plannedNeeds the cilockd signing daemon, which this mode does not run.
cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.
SLSA Build
- L0 Plannedcilockd on Linux
- L1 Plannedcilockd on Linux
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
ALPS
- 0 Plannedcilockd on Linux
- 1 Plannedcilockd on Linux
- 2 Plannedcilockd on Linux
- 3 Not plannedThe machine offers no hardware-attested signing key.
Linux workstation with a TPM 3 supported 3 planned 2 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 SupportedInlineSetup guide: An enrolled agent on a workstation
- L1 PlannedInlineSLSA v1 provenance type
- L2 Not plannedInlineA personal workstation is not a hosted build platform.
- L3 Not plannedInlineA personal workstation is not a hosted build platform.
Results by CI/lock mode
Inline. CI/lock runs and signs inside the build job or agent session.
SLSA Build
- L0 SupportedSetup guide: An enrolled agent on a workstation
- L1 PlannedSLSA v1 provenance type
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
ALPS
- 0 SupportedSetup guide: An enrolled agent on a workstation
- 1 SupportedSetup guide: An enrolled agent on a workstation
- 2 PlannedALPS 2 boundary attestation
- 3 Not plannedNeeds the cilockd signing daemon, which this mode does not run.
cilockd (Linux). A signing daemon outside the build or agent, with a hardware-held key.
SLSA Build
- L0 Plannedcilockd on Linux
- L1 Plannedcilockd on Linux
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
macOS with cilockd
macOS 27, Apple silicon, MDM-managed 0 supported 6 planned 2 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 Plannedcilockd (macOS)cilockd on macOS
- L1 Plannedcilockd (macOS)cilockd on macOS
- L2 Not plannedcilockd (macOS)A personal workstation is not a hosted build platform.
- L3 Not plannedcilockd (macOS)A personal workstation is not a hosted build platform.
Results by CI/lock mode
cilockd (macOS). A signing daemon with an App Attest key, outside the agent.
SLSA Build
- L0 Plannedcilockd on macOS
- L1 Plannedcilockd on macOS
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
macOS 27, Apple silicon, unmanaged 0 supported 6 planned 2 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 Plannedcilockd (macOS)cilockd on macOS
- L1 Plannedcilockd (macOS)cilockd on macOS
- L2 Not plannedcilockd (macOS)A personal workstation is not a hosted build platform.
- L3 Not plannedcilockd (macOS)A personal workstation is not a hosted build platform.
Results by CI/lock mode
cilockd (macOS). A signing daemon with an App Attest key, outside the agent.
SLSA Build
- L0 Plannedcilockd on macOS
- L1 Plannedcilockd on macOS
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
Intel Mac 0 supported 5 planned 3 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 Plannedcilockd (macOS)cilockd on macOS
- L1 Plannedcilockd (macOS)cilockd on macOS
- L2 Not plannedcilockd (macOS)A personal workstation is not a hosted build platform.
- L3 Not plannedcilockd (macOS)A personal workstation is not a hosted build platform.
ALPS
- 0 Plannedcilockd (macOS)cilockd on macOS
- 1 Plannedcilockd (macOS)cilockd on macOS
- 2 Plannedcilockd (macOS)cilockd on macOS
- 3 Not plannedcilockd (macOS)The machine offers no hardware-attested signing key.
Results by CI/lock mode
cilockd (macOS). A signing daemon with an App Attest key, outside the agent.
SLSA Build
- L0 Plannedcilockd on macOS
- L1 Plannedcilockd on macOS
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
ALPS
- 0 Plannedcilockd on macOS
- 1 Plannedcilockd on macOS
- 2 Plannedcilockd on macOS
- 3 Not plannedThe machine offers no hardware-attested signing key.
Windows with cilockd
Windows 11, TPM and Secure Boot, Intune-managed 0 supported 6 planned 2 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 Plannedcilockd (Windows)cilockd on Windows
- L1 Plannedcilockd (Windows)cilockd on Windows
- L2 Not plannedcilockd (Windows)A personal workstation is not a hosted build platform.
- L3 Not plannedcilockd (Windows)A personal workstation is not a hosted build platform.
Results by CI/lock mode
cilockd (Windows). A signing daemon with a VBS-enclave key, outside the agent.
SLSA Build
- L0 Plannedcilockd on Windows
- L1 Plannedcilockd on Windows
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
Windows 11, TPM and Secure Boot, unmanaged 0 supported 6 planned 2 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 Plannedcilockd (Windows)cilockd on Windows
- L1 Plannedcilockd (Windows)cilockd on Windows
- L2 Not plannedcilockd (Windows)A personal workstation is not a hosted build platform.
- L3 Not plannedcilockd (Windows)A personal workstation is not a hosted build platform.
Results by CI/lock mode
cilockd (Windows). A signing daemon with a VBS-enclave key, outside the agent.
SLSA Build
- L0 Plannedcilockd on Windows
- L1 Plannedcilockd on Windows
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
Windows Server 2025 on Azure Trusted Launch (self-hosted runner) 0 supported 7 planned 1 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 Plannedcilockd (Windows)cilockd on Windows
- L1 Plannedcilockd (Windows)cilockd on Windows
- L2 Plannedcilockd (Windows)cilockd on Windows
- L3 Not plannedcilockd (Windows)The worker is reused between jobs, so builds are not isolated.
Results by CI/lock mode
cilockd (Windows). A signing daemon with a VBS-enclave key, outside the agent.
SLSA Build
- L0 Plannedcilockd on Windows
- L1 Plannedcilockd on Windows
- L2 Plannedcilockd on Windows
- L3 Not plannedThe worker is reused between jobs, so builds are not isolated.
Windows without a TPM, or with Secure Boot off 0 supported 5 planned 3 not planned
The best result across CI/lock modes. The mode is named under each result.
SLSA Build
- L0 Plannedcilockd (Windows)cilockd on Windows
- L1 Plannedcilockd (Windows)cilockd on Windows
- L2 Not plannedcilockd (Windows)A personal workstation is not a hosted build platform.
- L3 Not plannedcilockd (Windows)A personal workstation is not a hosted build platform.
ALPS
- 0 Plannedcilockd (Windows)cilockd on Windows
- 1 Plannedcilockd (Windows)cilockd on Windows
- 2 Plannedcilockd (Windows)cilockd on Windows
- 3 Not plannedcilockd (Windows)The machine offers no hardware-attested signing key.
Results by CI/lock mode
cilockd (Windows). A signing daemon with a VBS-enclave key, outside the agent.
SLSA Build
- L0 Plannedcilockd on Windows
- L1 Plannedcilockd on Windows
- L2 Not plannedA personal workstation is not a hosted build platform.
- L3 Not plannedA personal workstation is not a hosted build platform.
ALPS
- 0 Plannedcilockd on Windows
- 1 Plannedcilockd on Windows
- 2 Plannedcilockd on Windows
- 3 Not plannedThe machine offers no hardware-attested signing key.
Source repositories
GitHub repository that only Pushgate can push to 0 supported 4 planned 0 not planned
The best result across CI/lock modes. The mode is named under each result.
Results by CI/lock mode
Pushgate Source VSA. Pushgate signs a SLSA Source verification summary for each push it admits.
GitHub repository that also accepts direct pushes 0 supported 4 planned 0 not planned
The best result across CI/lock modes. The mode is named under each result.
Results by CI/lock mode
Pushgate Source VSA. Pushgate signs a SLSA Source verification summary for each push it admits.
Full matrix: every environment, best result
| Environment | SLSA Build | SLSA Source | ALPS | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SLSA Build L0 | SLSA Build L1 | SLSA Build L2 | SLSA Build L3 | SLSA Source L1 | SLSA Source L2 | SLSA Source L3 | SLSA Source L4 | ALPS 0 | ALPS 1 | ALPS 2 | ALPS 3 | |
| GitHub Actions | ||||||||||||
| GitHub-hosted runner (Linux or macOS) | ||||||||||||
| GitHub-hosted runner, signing in a reusable workflow | ||||||||||||
| GitHub self-hosted runner | ||||||||||||
| GitHub-hosted runner (Windows) | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Other CI | ||||||||||||
| GitLab.com hosted runners | ||||||||||||
| GitLab self-managed | ||||||||||||
| Buildkite hosted agents | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| CircleCI cloud | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Jenkins | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Azure DevOps Microsoft-hosted agents | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| AWS CodeBuild (on-demand) | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Google Cloud Build | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Kubernetes | ||||||||||||
| Kubernetes pod (EKS, GKE or AKS) | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Kubernetes pod with a cilockd sidecar | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Developer machines and agents | ||||||||||||
| Pushgate (an agent pushes from a workstation) | ||||||||||||
| Developer workstation (macOS or Linux) | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Linux workstation with a TPM | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| macOS with cilockd | ||||||||||||
| macOS 27, Apple silicon, MDM-managed | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| macOS 27, Apple silicon, unmanaged | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Intel Mac | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Windows with cilockd | ||||||||||||
| Windows 11, TPM and Secure Boot, Intune-managed | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Windows 11, TPM and Secure Boot, unmanaged | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Windows Server 2025 on Azure Trusted Launch (self-hosted runner) | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Windows without a TPM, or with Secure Boot off | not evaluated | not evaluated | not evaluated | not evaluated | ||||||||
| Source repositories | ||||||||||||
| GitHub repository that only Pushgate can push to | not evaluated | not evaluated | not evaluated | not evaluated | not evaluated | not evaluated | not evaluated | not evaluated | ||||
| GitHub repository that also accepts direct pushes | not evaluated | not evaluated | not evaluated | not evaluated | not evaluated | not evaluated | not evaluated | not evaluated | ||||
Planned work
- Isolated provenance workflow
- A reusable GitHub workflow signs the provenance in a job the build steps cannot reach. It is the separate-signer mode, and the path to SLSA Build L3 on GitHub Actions. The workflow and the L3 verifier are not merged yet, and the provenance format fix is open. Tracking: testifysec/judge#9822, testifysec/judge#9827.
- ALPS 2 boundary attestation
- A trusted observer outside the agent records the sandbox that was applied, so a verifier can check it. Designed, not built. Tracking: testifysec/judge#8314.
- cilockd on Linux
- A signing daemon outside the build or agent, with a TPM-held key and a measured daemon identity. Tracking: testifysec/judge#9844, testifysec/judge#9845.
- cilockd on macOS
- A signing daemon whose key is attested by Apple App Attest, through a helper app the agent cannot drive. Tracking: testifysec/judge#9844, testifysec/judge#9846.
- cilockd on Windows
- A signing daemon whose key lives in a VBS enclave, with a TPM quote of the boot state. Tracking: testifysec/judge#9844, testifysec/judge#9847.
- Platform keyless signing beyond GitHub Actions
- The platform certificate authority accepts GitHub Actions, GitLab.com, Buildkite and CircleCI workload identities (#9839). No guide documents platform keyless signing on GitLab.com, Buildkite or CircleCI yet, so ALPS 1 there is listed as planned until one does. Tracking: testifysec/judge#9839.
- SLSA v1 provenance type
- CI/lock's slsa attestor emits predicateType https://slsa.dev/provenance/v1.0, which SLSA verifiers do not recognize. SLSA Build L1 and above are listed as planned until it emits https://slsa.dev/provenance/v1. Tracking: testifysec/judge#9827.
- Pushgate Source VSA
- Pushgate verifies every push it gates but does not yet issue a SLSA Source VSA for it. Designed, not built. Tracking: testifysec/judge#9931.
Not shown: the draft SLSA Build Environment and Dependency tracks. The Source track is evaluated only where CI/lock collects source-side evidence.
Generated from formal/slsa-tracks/matrix.json (sha256 be858e073977), a Lean 4 model of SLSA v1.2 (Build, Source) + working draft (BuildEnv, Dependency); ALPS 0.1. Each cell is a theorem. Supported cells were checked against shipped code on main at cbc65c7e41 on 2026-09-25.
Why the mode matters
Mermaid source
flowchart LR
A[Agent sandbox] -->|typed proof request| D[CI/lock service]
D -->|validate repo + commit + command + output| H[Non-exportable hardware identity]
H -->|keyless leaf + RFC 3161| P[TestifySec platform]
P --> E[Signed evidence]
G[No generic signing oracle] -.-> DIn the inline mode, CI/lock signs inside the job or agent session it observes, so code in that job can use the same signing identity. That is enough for ALPS 1, and for SLSA Build L2 once cilock emits the SLSA v1 provenance type (it emits v1.0 today; that fix is tracked above), and it is why no inline cell reaches Build L3 or ALPS 3. The separate-signer and cilockd modes move the signer out of reach, and they are the tracked work listed above.