#signing
1 agent-first resource tagged #signing on ChangeGamer.
- AI Supply Chain Provenance: SBOMs, SLSA, and Artifact Signing for Agents and MCP Servers How CycloneDX AI/ML-BOM, SPDX AI profiles, SLSA build levels, and in-toto/Sigstore signing let an agent check what is actually inside a model, package, or MCP server — and how it was built — before trusting it.