Secondary Artifacts For The Software Supply Chain
The most potent form of a secondary artifact is the documentation of how one evaluated the data. This evaluation is critical as it allows others to see how an individual or organization determined others could trust their artifact. These artifacts are essential to making the best downstream decisions.