Gradle Technologies is now Develocity — read the announcement

Artifact Governance

A trusted record of every artifact's journey through the delivery lifecycle.

Artifact governance flow showing signed facts, Policy Scan evaluation at each gate, and on-demand compliance queries.

Feature overview

Artifact Governance

Artifact Governance accumulates signed facts for every artifact as it moves through the delivery lifecycle. Each gate runs a Policy Scan that produces signed facts. Any downstream gate reads that result instead of re-evaluating from scratch. The full compliance set of signed facts is queryable on demand. When a security team, auditor, or AI agent asks whether an artifact cleared policy, the answer comes from signed facts that already exist. Lifecycle analytics surface delivery cycle times, release frequency, and dependency exposure across the organization. Gaps between build activity and production releases become visible before they become incidents. Policy Scan results show which artifact versions cleared policy and which carry unresolved risk.

Every governance decision is a signed fact

  • Every artifact has cryptographically verifiable in-toto Statements sealed in a Dead Simple Signing Envelope (DSSE).
  • No build can falsify its own signed facts because the server generates attestations independently.
  • Retain full control over the chain of trust by supplying your own signing keys.
  • Answer any compliance question from signed records, not by assembling data across different systems.
In-toto Statement JSON with labeled fields showing what a governance fact contains.

Build Scan facts prove what built it, not just what shipped

  • Gain full visibility into what produced an artifact, including build tool, toolchains, resolved dependencies, plugins, and publish targets that external scanners never observe.
  • Get an accurate bill of materials from actual dependency resolution, not probabilistic file name matching against declared dependencies in the published artifact.
  • Eliminate blind spots from shadowed libraries, renamed components, and first-party dependencies that external scanners cannot identify.
  • Write policies against captured build provenance: every signed fact becomes data the Policy Scan gates evaluate, from required toolchains to banned dependencies.
View the attestation types (opens in new tab)
Build Scan instrumentation capturing the full dependency graph compared to an external scanner limited to declared dependencies in the published artifact.

Every gate records a signed evaluation

  • Own compliance data in an open standard through Supply Chain Levels for Software Artifacts (SLSA) Verification Summary Attestations at every gate.
  • Simplify separation of duties because the server evaluates policies and signs attestations independently, reached over a REST API or GitHub Action at any stage of the delivery lifecycle.
  • Build an unbroken chain of trust across every gate because each signed result becomes a precondition the next gate verifies.
  • Compose reusable policy building blocks curated by your domain experts into one unified evaluation at every gate through label selectors.
Explore declarative policy authoring (opens in new tab)
Chain of trust diagram showing signed results accumulating across gates in the delivery lifecycle.

Govern with data from every system in your toolchain

  • Record deployment events, ITSM tickets, and CD pipeline signals as signed facts through Fact Connectors.
  • Enrich gate decisions with custom logic in any language through a REST endpoint via Fact Evaluators.
  • Replace bespoke compliance scripts across every CI/CD platform with a single trusted observer that records and evaluates independently.
  • RoadmapPrevent unapproved dependencies from entering the supply chain through Dependency Admission.
Explore Fact Connectors (opens in new tab)
Fact Connectors and Fact Evaluators contributing external data to the Governance Record as signed facts.
Analytics

Measure delivery velocity through your governance gates

  • Trace any artifact's journey through the delivery lifecycle from signed records.
  • Pinpoint where releases stall by tracking cycle time between signed gate transitions.
  • Identify which artifacts carry end-of-life dependencies across the organization before those libraries become a compliance liability.
  • RoadmapCompare build frequency against promotion frequency to surface gaps pipeline-log dashboards miss.
Learn how gate evaluations work (opens in new tab)
Artifact delivery journey showing gate topology from publish through production deployment with pass-fail status at each gate.
Agent Context

AI agents query governance facts before they act

  • Ground every agent action in trusted facts instead of training data.
  • Fix the highest-risk dependencies first through remediation by Develocity Agents.
  • Control what each actor can access down to the artifact and gate level through fine-grained authorization.
  • RoadmapBlock untrusted source code before it builds, keeping malicious dependencies out of privileged CI environments.
View the MCP tools (opens in new tab)
Agent context session showing governance data, the Develocity Agents remediation priority, and the agent opening a remediation PR with full context.

Resources

Supply Chain Observability with Develocity Provenance Governor
Blog
DevOps evolved: continuous GRC automation and observability
Blog

What's next

Get started today with a 30-day free trial of the entire Develocity product suite.

Start Free Trial

© 2026 Gradle, Inc. Gradle®, Develocity®, Build Scan®, and the Gradlephant logo are registered trademarks of Gradle, Inc.

Get an AI summary of Develocity: