Illustrative only - not an engagement finding
Unverified Build Inputs Can Produce an Untrusted Release
Critical
See where this finding applies on the diagrams: delivery zone [planned] · CP6 supply-chain gate
Illustrative only - not an engagement finding
Unverified Build Inputs Can Produce an Untrusted Release
- Business summary
- A release is trustworthy only when the reviewed source and every build input produce the same verifiable output. Changeable external inputs can alter production even when the application repository has not changed.
- Assessment profile
- Expected fix Verification
-
-
Expected fix Pin source, packages, actions, base images and build tools by immutable version, hash or digestVerification A clean rebuild from the same approved inputs must produce the expected digest
-
Expected fix Verify signatures and origin records before each input enters the buildVerification A changed hash, invalid signature or unidentified input must fail before the build uses it
-
Expected fix Run isolated builds with only the network access needed to retrieve approved inputsVerification The isolated build must be unable to retrieve an unapproved network input
-
Expected fix Bind the source revision, software inventory, build record and output digest in signed release evidenceVerification Signed release evidence must bind the source revision, software inventory, build record and output digest
-
Expected fix Release only the Azure Container Registry digest produced from those approved inputsVerification Only that approved digest may be released from Azure Container Registry
-