Provenance reference
Allowed providers:
local, github_actions, gitlab_ci, azure_pipelines, bitrise, codemagic.
Optional bounded fields: repository, commit SHA, run ID, branch and tag. The CLI detects provenance from an allowlisted subset of provider environment variables. Secrets and arbitrary environment variables are never provenance.
Provenance is descriptive, not authorization. Build content SHA-256 and parsed artifact identity remain authoritative.