NIST SSDF: PS — Provenance / SBOM Recorded
errorssdf_ps_provenance_recorded
Provenance data (e.g. an SBOM) for each release is recorded (PS.3).
Formula
G(Release → P(provenance_recorded)) Why it matters
SSDF PS.3: archive and protect each software release, and collect provenance data (such as a software bill of materials).
Examples
passes the practice's evidence is present
fails the required secure-development step is absent
Use it
ponens policies add ssdf_ps_provenance_recorded --into ./trace.json
ponens trace check ./trace.json