Build from signed source

This policy checks if the build was done from a signed commit.

Control evaluation result

Status

Evaluation result after comparing the policy with the current state of the asset
0 Violations

Update the attestation using the following command
devguard-scanner attest --predicateType "https://slsa.dev/provenance/v1" <json file>
Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version d51ba4d3f2ef56cdcc49e35bed410d86e1263d7a