Skip to content

Provenance

QuollVault records where an upload came from without making CI metadata authoritative.

Supported providers: local, github_actions, gitlab_ci, azure_pipelines, bitrise, codemagic.

When available, provenance can include repository, commit SHA, run ID, branch and tag. Provider detection is best-effort and server validation bounds accepted values. Artifact identity and SHA-256 remain authoritative even when provenance is absent.

Derived re-signed Builds record normal upload provenance plus source-Build lineage.