SYSE.32:11 - SoTA-Echoing
For “What must a consumer verify before trusting the promoted artifact?”, adopt the bounded procedure in SLSA v1.2 Verifying artifacts. Reject signature-only acceptance: section 4.4 binds the check to actual bytes and configured expectations. This requires trust maintenance and still does not prove application correctness.
For transfer, adapt the same-artifact line in DORA Deployment automation. The competing convenience is rebuilding per environment. Separating artifact and configuration preserves the tested subject; destinations that truly require different bytes must qualify those outputs instead.
Reopen the arrangement when packaging, consumer boundaries, trust roots, builder identity, artifact retention or the relied-on evidence conditions change. A new source version or a security event may require reassessment; an old valid signature is not perpetual permission to use an artifact.