Join our Newsletter — 33% off our NHI Course

Supply-chain attestations: what evidence do CI gates actually trust?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Recent Trivy and LiteLLM incidents show the difference between what a workflow intended to run and what evidence it can prove, according to Testifysec, especially when signatures, attestations, and trusted producers are confused. The security problem is not absence of evidence but over-trusting evidence without policy-bound producer identity and scope control.

Editorial analysis by NHI Mgmt Group, based on content published by Testifysec: “The Signed Record We Didn’t Have in March”.

Key questions

Q: What breaks when signed attestations are treated as proof of trusted execution?

A: The main failure is assuming authenticity proves authority.

Q: Why do supply-chain incidents expose identity governance gaps in CI/CD?

A: Because CI/CD increasingly depends on machine identities to create, sign, and publish evidence.

Q: What signs show that an attestation model is too weak for release decisions?

A: Look for broad producer permissions, unclear subject binding, shared signing paths, and evidence that cannot be tied back to a specific workflow boundary.

Practitioner guidance

  • Define trusted producer identities for evidence Restrict which build, agent, or signing identities are allowed to create attestations for release decisions, and bind each one to a specific evidentiary scope.
  • Verify the attested subject, not just the signature Check that the recorded subject matches the artifact or change you intended to assess, then confirm the signer is authorised to speak for that subject.
  • Separate policy signing from evidence production Do not let the same workflow path publish policy, generate evidence, and approve activation without independent controls over each role.

Bottom line: Signed attestations are only useful when the producer identity, subject binding, and policy scope are all tightly governed.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Producer trust is the real control plane in supply-chain evidence. Attestations only work when the organisation has explicitly defined which producer identities may create evidence for which claims. If the trusted signer, workflow, or agent can be repurposed, the evidence remains syntactically valid but governance-invalid. The practitioner conclusion is to treat producer identity as a release gate, not a background implementation detail.

A few things that frame the scale:

  • Breaches involving third parties rose to 48% of all breaches, a 60% increase on the previous year, according to Verizon's 2026 Data Breach Investigations Report.

A question worth separating out:

Q: Should teams trust a signed build artifact without checking the producer and scope?

A: No. A signed artifact is only useful when the signing identity, the subject of the statement, and the policy around both are explicitly controlled. Teams should treat producer trust, capture scope, and release authority as separate decisions, because a signature alone does not prove safe provenance.

👉 Read our full editorial: Supply-chain attestations fail when producer trust is assumed



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.