Artifact Management covers practices for storing, versioning, signed provenance and access control of build artifacts. It ties CI/CD, repository services and governance to ensure consistency, reproducibility and security across the software supply chain.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Artifact management organizes build artifacts and binary packages so versions, origin, access, and handoff remain traceable across the supply chain.
As CI/CD spread, source-code repositories were no longer enough: teams needed to store, proxy, and release built packages, container images, and other binary artifacts separately from the build while keeping them controlled. Repository managers and governance practices emerged around versioning, permissions, replication, and provenance; SLSA further centers supply-chain integrity and signed evidence.
Think of artifact management as a controlled handoff layer between build and use. The CI/CD pipeline produces an artifact, stores it in a repository with version, metadata, and signature, and applies access rules. Later, deployments, package managers, or clusters consume exactly that approved copy; governance checks which source, which build, and which release stand behind it.
A packaged build result such as a package, image, or binary intended for distribution.
Metadata and attestations show origin, build context, and immutability.
Each published state gets a distinct form that can be retrieved later.
Rules determine who may store, read, mirror, or release artifacts.
Intermediate repositories deliver, cache, or replicate artifacts from internal and external sources.
This topic matters when multiple teams publish packages or images, releases must move between build, test, and production, or audits require origin evidence. Its value increases with clear policies for signatures, retention, and promotion. Without consistent verification, however, shadow copies, stale artifacts, and extra operational work from cache, mirror, and cleanup workflows quickly appear.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.