Provenance
QuollVault records where an upload came from without making CI metadata authoritative.
Supported providers: local, github_actions, gitlab_ci, azure_pipelines, bitrise, codemagic.
When available, provenance can include repository, commit SHA, run ID, branch and tag. Provider detection is best-effort and server validation bounds accepted values. Artifact identity and SHA-256 remain authoritative even when provenance is absent.
Derived re-signed Builds record normal upload provenance plus source-Build lineage.