I. Assurance Is Not Where Systems Fail — Translation Is
Modern software governance fails less from a lack of rules than from a surplus of handoffs. Specifications are verified, policies are approved, reviews are conducted—yet the artifact that reaches users, or the system that runs in production, quietly escapes the constraints that were meant to bind it. The literature surveyed here converges on a single diagnosis: assurance decays as it crosses translation layers, and governance survives only where systems are designed to refuse that decay.
This is not a story about bad actors or insufficient awareness. It is a story about systems that continue to offer convenient exits—manual configuration, unsigned artifacts, informal evidence flows, discretionary overrides—long after they claim to have eliminated them.
II. Build Pipelines as Claims, Not Processes
The foundational insight of in-toto is that build pipelines are not merely operational workflows; they are assertions about history. Organizations claim that certain steps occurred, in a certain order, by certain actors, using certain materials. Historically, these claims dissolve once artifacts leave the build environment. Consumers cannot verify whether the documented pipeline actually ran.
in-toto binds each step cryptographically, producing signed, linkable metadata that travels with the artifact. The governance move is not increased transparency, but removal of the option to ship without provenance. An artifact either carries its history, or it does not move.
This reframing—pipelines as claims that must survive transit—sets the pattern for everything that follows.
III. Adoption Friction as a Governance Failure Mode
Provenance mechanisms fail if they are too costly to use correctly. Sigstore begins from a mundane but decisive observation: signing exists, but key management does not survive automation. Under CI pressure, teams quietly weaken or abandon signing practices.
Sigstore’s contribution is architectural, not moral. By replacing long-lived keys with OIDC-bound identity, ephemeral certificates, and a transparency log, it removes the most common excuse for noncompliance. The option eliminated is not misuse, but non-use justified by friction. Governance holds because enforcement is redesigned to align with how systems actually run.
IV. When the Center Cannot Be Trusted
Scale introduces a harsher reality: compromise is inevitable. Survivable Key Compromise in Software Update Systems (the basis of TUF) rejects the idea that a single trusted repository or key can anchor governance. Instead, it relocates enforcement to clients through role separation, threshold signatures, and explicit recovery paths.
The critical shift is where refusal lives. Even if the repository insists an update is valid, clients refuse it unless trust invariants are satisfied. The option removed is submission to a corrupted center.
Diplomat extends this logic to community repositories, where operational convenience historically demanded broad online authority. By restructuring trust through delegation, Diplomat fragments power and limits blast radius. What disappears is monolithic authority justified by scale. Governance survives because no single compromise can silently redefine truth.
V. Cost, Scale, and the Quiet Erosion of Enforcement
Even well-designed protections fail when they are expensive. Mercury exposes a recurring decay pattern: rollback protection exists, but metadata overhead grows with repository size and update frequency. Under pressure, clients weaken or disable freshness checks.
Mercury’s contribution is not conceptual but practical. By making rollback resistance bandwidth-efficient, it preserves enforcement under real constraints. The removed option is weakening guarantees in the name of efficiency. Governance survives because refusal is made cheap enough to keep.
VI. The Source–Binary Gap and the Myth of Trustworthy Builds
The most uncomfortable translation layer lies between reviewed source code and delivered binaries. Reproducible Builds and Insights from an Independent Verifier for Arch Linux shows that, in practice, this gap is wide. Independent rebuilding uncovers real divergences—evidence that without external verification, build integrity remains an honor system.
Reproducibility turns this gap into an enforceable boundary. The option removed is trusting build environments simply because they are institutionalized or familiar. Governance survives because claims about correspondence can be independently checked—or refused.
VII. Runtime Evidence and the Fragility of Trust After Deployment
CI/CD governance does not end at release. Runtime systems introduce their own translation layers, where assurance often collapses silently.
Evidence Tampering and Chain of Custody in Layered Attestations demonstrates that even correct measurements can become untrustworthy as evidence is bundled and transported. The paper’s response is not better audits, but protocol transformation: evidence flows that permit undetectable tampering are made structurally unavailable. Trust survives because certain paths no longer exist.
This theme recurs in Verified Configuration and Deployment of Layered Attestation Managers, which targets the gap between verified protocol designs and their real-world deployment. Manual configuration reintroduces discretion precisely where verification aimed to remove it. By synthesizing deployment artifacts directly from verified specifications, the system eliminates configuration as a site of judgment.
Earlier in the chain, An Infrastructure for Faithful Execution of Remote Attestation Protocols and Formally Verified Bundling and Appraisal of Evidence confront semantic drift. Protocol intent decays when execution and appraisal are hand-implemented. Verified compilers, virtual machines, and appraisal logic remove the option to “interpret” evidence informally.
Finally, PDRIMA challenges the illusion that boot-time integrity implies runtime integrity. By enforcing policy-driven, continuous measurement inside the TEE, it removes the option to declare trust once and carry it forward indefinitely. Integrity must continually re-justify itself.
VIII. Governance That Works Removes Options
Across CI/CD pipelines, update systems, and runtime attestation, the same pattern holds. Governance survives not because actors are better trained or more ethical, but because systems are redesigned so that certain failures cannot be silently propagated.
What unites these papers is restraint. They do not promise perfect security or flawless behavior. They assume error, compromise, and pressure. Their success lies in narrowing translation layers until discretion runs out.
For Phase 4 thinking, the implication is direct. Pipelines, build systems, update clients, and attestation mechanisms are not neutral infrastructure. They are governance substrates. Where they refuse to carry unverifiable, unauthenticated, or semantically ambiguous artifacts, governance holds. Where they do not, trust becomes a narrative told upstream—long after the system has already moved on.
Sources
- Torres-Arias et al., in-toto: Providing farm-to-table guarantees for bits and bytes, USENIX Security, 2019.
- O’Connor et al., Sigstore: Software Signing for Everybody, ACM CCS Workshop, 2022.
- Cappos et al., Survivable Key Compromise in Software Update Systems, ACM CCS, 2010.
- Kuppusamy et al., Diplomat: Using Delegations to Protect Community Repositories, USENIX NSDI, 2016.
- Cappos et al., Mercury: Bandwidth-Effective Prevention of Rollback Attacks, USENIX ATC, 2017.
- Fichtner et al., Reproducible Builds and Insights from an Independent Verifier for Arch Linux, arXiv, 2024–25.
- Garrison et al., Evidence Tampering and Chain of Custody in Layered Attestations, arXiv, 2024.
- Dodds et al., Verified Configuration and Deployment of Layered Attestation Managers, SEFM / Zenodo, 2024.
- Elphinstone et al., An Infrastructure for Faithful Execution of Remote Attestation Protocols, arXiv, 2020.
- Rizk et al., Formally Verified Bundling and Appraisal of Evidence for Layered Attestations, Springer, 2022–23.
- Li et al., PDRIMA: A Policy-Driven Runtime Integrity Measurement and Attestation Approach, arXiv, 2025.
Member discussion: