Skip to harness content
Open technical reference map

Production domain 07

CI/CD, Version Control & Quality

3 capabilities and 3 controls define the canonical obligation set for this domain.

Domain 07Dependencies: Security & Data Protection
Canonical pathcontrols/production-layers.v2.jsonRevision69bab1cInspect source

Applicability and claim boundary

This domain defines obligations. It does not prove that a specific repository or run satisfies them.

Applicability
Assess this domain when the authorized workload can affect its capabilities. Resolve every control as required, potentially affected, or not applicable before completion.
Proof level
The accepted formats below identify possible evidence inputs. A format alone does not establish semantic or authoritative assurance; provenance and the commissioned proof contract set the supported level.
Claim boundary
Static controls are requirements, not execution evidence, provider attestation, or proof of production readiness.

Capabilities

quality-gates

Quality Gates

Block unverified changes with attributable checks and governed overrides.

software-supply-chain

Software Supply Chain

Scan and govern dependencies, source, secrets, and infrastructure inputs.

release-provenance

Release Provenance

Bind release artifacts to source, build, and approval identity.

Controls

CI-GATES-001Quality Gates

Required checks block unverified changes and overrides are auditable.

Accepted evidence format: Command output
CI-SUPPLYCHAIN-001Software Supply Chain

Dependencies, secrets, code, and infrastructure are scanned.

Accepted evidence format: Command output
CI-PROVENANCE-001Release Provenance

Release artifacts are attributable to source, build, and approval identity.

Accepted evidence format: Artifact, Provider report