• The Chainguard assessment team concluded that the source, build, and provenance portions of the Argo CD supply chain all achieved SLSA level 3.
  • The Chainguard assessment of Prometheus found the project yielded SLSA Level 3 for both Source and Build sections.
  • Provenance is an important piece of the supply chain that allows the consumers of an artifact to verify its authenticity. The Chainguard assessment team recommends that the Prometheus maintainers implement provenance generation within the Prometheus build infrastructure.