Skip to main content

Document metadata

Status
Maintained
Approval
Approved
Version
1.0
Classification
PUBLIC
Owner
Lightning IT Documentation Maintainers
Approver
Lightning IT Security and Compliance Maintainers
Audience
customers, security reviewers, engineering contributors
Last reviewed
Next review
(Semiannual)

Dependency and supply chain

Current implementation — docs.l-it.io. Release validation creates reproducible CycloneDX inventories, checks repository and dependency licenses, and binds provenance attestations to immutable release artifacts. Evidence is valid only for the named workflow run, commit, and digest.

Planned improvement. Portfolio-wide dependency, Renovate, signing, and SBOM coverage will be reported only after every product has an evidence-linked record. Owner: Supply-chain Owner.

No claim of SLSA level, continuous monitoring, or complete vulnerability absence is made.