Port infrastructure representing software moving through a controlled supply chain

Software supply chain

Evidence that follows the Linux artifact

Keep the recipe, build record, artifact identity, CycloneDX inventory, and VM test results connected. Reviewers can see what was built and what was actually tested without relying on a release note alone.

CycloneDX JSONHash-bound inventoryVM test records

Build evidence from the artifact outward

OpenFactory generates a software inventory for supported Linux image builds and keeps artifact and verification records alongside the result. The workflow is designed to fail visibly when evidence is incomplete rather than silently labeling unknown packages as safe.

CycloneDX inventory

Generate a machine-readable package inventory for supported ISO and disk-image workflows.

Artifact identity

Tie the inventory and verification record to the built output with stable identifiers and hashes.

Runtime checks

Boot the produced image in a VM and retain the result of agreed functional or visual checks.

Explicit coverage

Preserve inventory coverage and unknown results so security reviewers can distinguish missing evidence from an unaffected package.

A reviewable evidence chain

Each step contributes a different fact. Together they make a release review more concrete.

  1. 01

    Declare

    Version the Linux recipe and the validation expectations for the system.

  2. 02

    Produce

    Build the artifact, generate its CycloneDX sidecar, and record artifact identifiers and hashes.

  3. 03

    Verify

    Boot the actual result, run checks, and retain both passing and unresolved evidence for review.

Supply chain questions

Does OpenFactory claim fully deterministic builds?

No. OpenFactory makes inputs, artifacts, and checks reviewable, but does not market every image build as bit-for-bit deterministic.

Are artifacts and SBOMs cryptographically signed?

Artifact hashes and hash-bound CycloneDX records are available today. Broader signing and external attestation claims are not presented as generally available.

Does this replace our security scanner?

No. The inventory and artifact evidence can support your review and scanner workflows. OpenFactory also performs supported advisory assessment, but specialist controls remain part of the customer security program.

Prove one release path end to end

Use one representative image to identify which evidence OpenFactory produces today and which controls still belong in your surrounding process.

Scope an evidence pilot