Document metadata
- Status
- Maintained
- Approval
- Approved
- Version
- 1.0
- Classification
- PUBLIC
- Owner
- Lightning IT Documentation Maintainers
- Approver
- Lightning IT Security and Compliance Maintainers
- Audience
- customers, security reviewers, engineering contributors
- Last reviewed
- Next review
- (Semiannual)
Dependency and supply chain
Current implementation — docs.l-it.io. Release validation creates reproducible CycloneDX inventories, checks repository and dependency licenses, and binds provenance attestations to immutable release artifacts. Evidence is valid only for the named workflow run, commit, and digest.
Planned improvement. Portfolio-wide dependency, Renovate, signing, and SBOM coverage will be reported only after every product has an evidence-linked record. Owner: Supply-chain Owner.
No claim of SLSA level, continuous monitoring, or complete vulnerability absence is made.