# Verify what enters the release

Taiga Learning · Worksheet
https://taiga.training/en/lessons/supply-chain/

Use fictional or approved information. Do not put secrets in this worksheet.

## Learning objectives
- Distinguish a dependency inventory from security evidence.
- Explain why a package name and a successful install are insufficient.
- Trace an artifact to its source and build process.

## Exercise
Choose a fictional CSV export change that adds a package. Write an acceptance note covering necessity, exact package identity, version, license, maintenance, vulnerability findings, and install behavior. Draw the path from the reviewed commit to the deployed artifact.

## Your response
- Scenario and scope:
- Assumptions and open questions:
- Proposed answer or decision, with reasons:

## Verify your response
| Claim or criterion | Evidence or test | Result or gap | Owner |
| --- | --- | --- | --- |
| | | | |
| | | | |
| | | | |

## Next action
- Action, owner, and date:
- When will you review this response?

## Principle to retain
Review the dependencies and the build path. A secure source change can still produce an untrusted release artifact.

## Sources
- [SLSA: provenance](https://slsa.dev/spec/v1.2/provenance)
- [NIST: Secure Software Development Framework](https://csrc.nist.gov/pubs/sp/800/218/final)

This worksheet supports learning. Completing it does not itself authorize a production change.
