# OWASP Recommends Software Artifact Signing

OWASP’s DevSecOps guideline recommends that software suppliers sign release artifacts, provide verifiable build provenance, and automate verification before release or deployment. The guidance does not create a statutory procurement requirement, appropriation, or compliance deadline, but it signals controls that government customers may increasingly expect from contractors—particularly for software used in critical systems.

- Procurement teams can assess whether software offers include artifact signing, verifiable provenance, and automated verification as part of supply-chain security reviews; the guideline is a recommendation, not a mandate.
- Contractors serving government customers may benefit from documenting how they generate and verify build provenance, especially for critical-system deliveries.
- Chainguard and GitHub are examples of tools and services supporting signed artifacts, attestations, or provenance workflows; evaluate their capabilities against the needs of the specific acquisition.

**Jurisdictions:** international
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** October 06, 2026

### Vendors
- Chainguard (Produces signed minimal container images with SLSA-backed provenance)
- GitHub (Provides artifact attestations and hosted workflows for build provenance and signing)

### Sources
- [Artifact Signing and Provenance - OWASP DevSecOps Guideline](https://owasp.github.io/DevSecOpsGuideline/2-Process/2-3-Build/2-3-6-Supply-Chain-Security/2-3-6-2-Artifact-Signing-and-Provenance) - GitHub