{"apiVersion":"provenance.aureliasrs.ca/v1","kind":"Artifact","metadata":{"digest":"sha256:abc123def456789012345678901234567890abcdef123456789012345678901234","name":"s3-bucket-module-v1.0.0.tar.gz","channel":"terraform-modules","release":"v1.0.0","publishedAt":"2026-01-15T10:00:00Z"},"spec":{"digests":[{"algorithm":"sha256","canonical":true,"value":"abc123def456789012345678901234567890abcdef123456789012345678901234"},{"algorithm":"sha512","value":"def789ghi012345678901234567890abcdef123456789012345678901234567890123456789abcdef012345"},{"algorithm":"blake3","value":"jkl678mno901234567890abcdef123456789012345678901234"}],"signatures":[{"algorithm":"pgp","keyFingerprint":"1234 5678 90AB CDEF 1234 5678 90AB CDEF 1234 5678","keyId":"4096R/ABCD1234","keyLocations":["https://keys.openpgp.org/vks/v1/by-fingerprint/1234567890ABCDEF","https://keybase.io/aureliasrs","https://keys.aureliasrs.ca/pgp/primary.asc"],"signature":"-----BEGIN PGP SIGNATURE-----\niQIzBAABCAAdFiEEexamplefingerprinthere1234567890ABCDEF\nexampleSignatureDataHere1234567890ABCDEFGHIJKLMNOPQRSTUV\nWXYZ0123456789abcdefghijklmnopqrstuvwxyz1234567890ABCD\nEFGHIJKLMNOPQRSTUVWXYZexample1234567890ABCDEFGHIJKLMexam\npleSignatureBlockContinuesHere567890ABCDEFGHIJKLMNOPQRSTUV\nWXYZfinalExampleBlock1234567890==\n-----END PGP SIGNATURE-----\n","signedAt":"2026-01-15T10:00:00Z","signerId":"AureliaSRS Primary Key"},{"algorithm":"pgp","keyFingerprint":"9876 5432 10FE DCBA 9876 5432 10FE DCBA 9876 5432","keyId":"2048R/WXYZ9876","keyLocations":["https://keys.openpgp.org/vks/v1/by-fingerprint/987654321 0FEDCBA"],"signature":"-----BEGIN PGP SIGNATURE-----\niQEzBAABCAAdFiEEbackupKeyfingerprinthere9876543210FE\nbackupSignatureDataHere9876543210FEDCBAZYXWVUTSRQPONMLK\nJIHGFEDCBA0123456789backupExampleData9876543210FEDCBAZY\nXWVUTSRQPONMLKJIHGFEDCBAbackup==\n-----END PGP SIGNATURE-----\n","signedAt":"2026-01-15T10:00:00Z","signerId":"AureliaSRS Backup Key"}],"externalAttestations":[{"attesterId":"Sigstore Rekor Transparency Log","logUrl":"https://rekor.sigstore.dev/api/v1/log/entries/1234567890abcdef","statement":"Artifact logged in public transparency log with entry ID 1234567890abcdef","timestamp":"2026-01-15T10:05:00Z","type":"transparency-log"},{"attesterId":"Trivy Security Scanner","reportUrl":"https://provenance.aureliasrs.ca/security-reports/sha256-abc123def456.txt","statement":"No critical vulnerabilities detected. 0 high, 0 medium, 2 low findings.","timestamp":"2026-01-15T11:00:00Z","type":"vulnerability-scan"}],"provenance":{"buildEnvironment":{"architecture":"x86_64","containerRuntime":"docker-24.0.7","kernel":"5.15.0-91-generic","os":"Ubuntu 22.04.3 LTS","sboms":[{"digest":"sha256:buildenv789abc012345678901234567890abcdef123456","format":"cyclonedx","url":"https://provenance.aureliasrs.ca/sbom/build-env-sha256-abc123-cyclonedx.json","version":"1.5"},{"digest":"sha256:buildenv890bcd123456789012345678901234567890bcdef","format":"spdx","url":"https://provenance.aureliasrs.ca/sbom/build-env-sha256-abc123-spdx.json","version":"2.3"}],"toolchain":[{"name":"terraform","version":"1.6.6"},{"name":"tflint","version":"0.50.0"},{"name":"git","version":"2.43.0"}]},"buildMetadata":{"buildDuration":"480s","buildNode":"build-node-ca-01","completedAt":"2026-01-15T09:58:00Z","reproducible":true,"startedAt":"2026-01-15T09:50:00Z"},"buildSystem":{"commit":"1a2b3c4d5e6f7890abcdef1234567890abcdef12","giteaVersion":"1.21.5","ref":"refs/tags/v1.0.0","repository":"Internal (private)","type":"gitea-actions","workflow":".gitea/workflows/release.yaml"},"builder":{"id":"Gitea Actions","runner":"self-hosted-runner-01","runnerVersion":"v3.2.1","version":"ubuntu-22.04"},"jurisdiction":{"buildLocation":"ca-central-1 (AWS Canada - Montreal)","dataResidency":"Canada","legalEntity":"AureliaSRS Inc."},"sbom":{"digest":"sha256:sbom123456789abcdef012345678901234567890abcdef","format":"cyclonedx","url":"https://provenance.aureliasrs.ca/sbom/sha256-abc123def456.json"},"signingSystem":{"jurisdiction":"Canada","keyManagement":"hardware-security-module","type":"gpg"}},"verification":{"attestationsVerified":true,"digestVerified":true,"lastVerifiedAt":"2026-01-16T06:00:00Z","signatureVerified":true,"verificationLog":"https://provenance.aureliasrs.ca/verification-logs/sha256-abc123.txt","verificationMethod":"automated"}},"links":{"html":"/channels/terraform-modules/releases/v1.0.0/sha256-abc123def456789012345678901234567890abcdef123456789012345678901234/","release":"/channels/terraform-modules/releases/v1.0.0/","channel":"/channels/terraform-modules/releases/"}}