🔒All inputs are processed locally in your browser. Nothing is transmitted, stored, or logged. Inputs disappear when you close the tab.

OCG-Industries Showcase · Cluster ⑩ Software and Cybersecurity Supply Chain

CI/CD Build
Provenance

Enter a build descriptor once as the original and once as a rebuild, four fields each: source reference, builder id, entrypoint, and artifact name. This tool fingerprints both descriptors, tells you whether the rebuild reproduces the original bit for bit, counts which of the four fields moved, and reports what SLSA build level the descriptor set can actually support given how complete it is and whether it reproduced. A questionnaire answer that says "SLSA 3" is a claim. A rebuild that reproduces the same descriptor is a chain you can walk from commit to artifact.

Data: SLSA v1.0 Build Track · in-toto attestation predicate

Build Descriptors STEP 1

Original build

Rebuild

The build level you were told to expect, or the one on the questionnaire
Status
Reproduced, mutated, or incomplete
Mutated Fields
Of 4 fields, how many moved
Level Supportable
What the descriptor set can back up
Detail
Descriptor A digest (mutation detector, not a cryptographic digest)
Descriptor B digest (mutation detector, not a cryptographic digest)
Reproduced
Mutated field count
Field completeness (of 4)
SLSA level claimed
Level supportable
Status
Policy Mandate v2.0 · what is this?