HomeCybersecurityBuild Pipeline Provenance: Signed Artifacts vs Silent Fan-Out Compromise

Build Pipeline Provenance Simulator

Compare an undefended CI/CD pipeline (a compromised build system silently propagates a malicious artifact to every downstream deployment destination) against a provenance-gated pipeline (each destination verifies a signed commit-hash attestation and blocks the tampered artifact).

Cybersecurity3DModerate60 FPS
build-pipeline-provenance-signed-artifacts-vs-silent-fan ↗ Open standalone
⚙ Under the hood

A 3D CI/CD pipeline where one build system fans a single artifact out to six downstream deployment destinations. Compromise the build step and toggle between an undefended pipeline — where the malicious artifact silently reaches every destination at once — and a provenance-gated pipeline, where each destination verifies a signed commit-hash attestation against an approved list and blocks the tampered build before it ever runs, with a live compromised-deployments counter comparing both.

Three.jscybersecurityCI/CDsupply chain securitybuild system compromiseprovenancecommit attestationSLSADevSecOps

3D · Three.js / WebGL renderer · 60 FPS target · runs fully client-side, no install

What did you find?

Add reproduction steps (optional)