# Supply-chain qualification

> Verify dependencies, bundles, provenance, signatures, updates, and rollback.

Source: https://accd.github.io/verchestra/docs/qualification/supply-chain-qualification/
Content digest: `sha256:dfd7bc1986db97bb1dcf3d3a00454f347e528bf00bf327327be9b27dd8421a11`

Supply-chain evidence covers locked dependencies, action pinning, component manifests, SBOM generation, provenance, signature verification, TUF metadata, offline closure, transactional activation, health checks, and rollback targets.

T76 will assemble these controls into a reproducible candidate. T77 will verify the exact candidate independently and record the human release decision.

Until that sequence succeeds, the repository remains source development at `0.0.0-qualification`.
