{
 "_type": "https://in-toto.io/Statement/v1",
 "subject": [
  {
   "name": "corecp-nginx-modsecurity_3.0.16+nginx1.28.3+corecp1_amd64.deb",
   "digest": {
    "sha512": "4920bad629cddb24b4a73762e8f9822418b83dab4ceac5370d842db79942fa8813adaa802943383fd32f52e153bf39c73bd3ef7afbc7289e21ecc426ad2a1d8a",
    "sha256": "91491cfff3f08e20685be2666c914e44acfdc0e0031affec8769f3b3ab83ce47"
   }
  }
 ],
 "predicateType": "https://slsa.dev/provenance/v1",
 "predicate": {
  "buildDefinition": {
   "buildType": "https://corecp.dev/build/sbuild/v1",
   "externalParameters": {
    "package": "corecp-nginx-modsecurity",
    "version": "3.0.16+nginx1.28.3+corecp1",
    "architecture": "amd64",
    "buildScript": "infra/build-server/sbuild/recipes/modsecurity3.sh",
    "sourceCommit": null,
    "sourceCommitNote": "unknown: this build ran from a source tree with no git history (the build server holds an rsync copy), and no caller passed CORECP_SOURCE_COMMIT",
    "recipe": "modsecurity3"
   },
   "internalParameters": {
    "toolchain": {
     "binutils": "2.46-3ubuntu2",
     "dpkg-dev": "1.23.7ubuntu1",
     "g++-15": "15.2.0-16ubuntu1",
     "gcc-15": "15.2.0-16ubuntu1",
     "libc6-dev": "2.43-2ubuntu2.4",
     "make": "4.4.1-3"
    },
    "environment": {
     "mode": "sbuild-unshare",
     "network": "disabled during the build (sbuild enable_network=0)",
     "chrootTarballSha256": "83ed65faa9a093e4a8dbc8f95453aecfffc39fc4d19b626fdc737096eb0d6f78",
     "buildcache": {
      "state": "hit",
      "key": "1580a72355ac4506413939a971e493d97776155b62a6a74988fecc587c85f7ea"
     }
    }
   },
   "resolvedDependencies": [
    {
     "name": "inputs/modsecurity-v3.0.16.tar.gz",
     "uri": "https://github.com/owasp-modsecurity/ModSecurity/releases/download/v3.0.16/modsecurity-v3.0.16.tar.gz",
     "digest": {
      "sha256": "739be3c71b1939f14e91afe1eeae654acbd440da11bd29790458840bc315b4c0"
     },
     "annotations": {
      "verified": "sha256 pinned in infra/build-server/sbuild/recipes/modsecurity3.sh after verifying upstream's OpenPGP signature (key 0B2BA1924065B44691202A2AD286E022149F0F6E)"
     }
    },
    {
     "name": "inputs/ModSecurity-nginx-v1.0.4.tar.gz",
     "uri": "https://github.com/owasp-modsecurity/ModSecurity-nginx/releases/download/v1.0.4/ModSecurity-nginx-v1.0.4.tar.gz",
     "digest": {
      "sha256": "6bdc7570911be884c1e43aaf85046137f9fde0cfa0dd4a55b853c81c45a13313"
     },
     "annotations": {
      "verified": "sha256 pinned in infra/build-server/sbuild/recipes/modsecurity3.sh after verifying upstream's OpenPGP signature (key 0B2BA1924065B44691202A2AD286E022149F0F6E)"
     }
    },
    {
     "name": "inputs/nginx-1.28.3.tar.gz",
     "uri": "https://nginx.org/download/nginx-1.28.3.tar.gz",
     "digest": {
      "sha256": "2c96a946bfb0882a21744ed429770a2123ae1828c7c48665092993ddee91a918"
     },
     "annotations": {
      "verified": "sha256 pinned in infra/build-server/sbuild/recipes/modsecurity3.sh after verifying upstream's OpenPGP signature (key 43387825DDB1BB97EC36BA5D007C8D7C15D87369); headers only — no nginx binary is packaged"
     }
    }
   ]
  },
  "runDetails": {
   "builder": {
    "id": "https://build.corecp.dev/corecp-build",
    "builderDependencies": [
     {
      "name": "resolute-amd64.tar.zst",
      "digest": {
       "sha256": "83ed65faa9a093e4a8dbc8f95453aecfffc39fc4d19b626fdc737096eb0d6f78"
      }
     },
     {
      "name": "corecp-nginx-modsecurity_3.0.16+nginx1.28.3+corecp1_amd64.buildinfo",
      "digest": {
       "sha256": "ec01d1401cdffc9f2b6bf27bd10075d989f4e38e89ea610cbc259a027da1c591"
      },
      "annotations": {
       "installedBuildDepends": 133
      }
     }
    ]
   },
   "metadata": {
    "invocationId": "corecp-nginx-modsecurity-3.0.16+nginx1.28.3+corecp1-91491cfff3f08e20",
    "startedOn": "2026-09-27T05:58:29Z",
    "finishedOn": "2026-09-27T05:58:30Z"
   }
  }
 },
 "_note": "SLSA Build L1 with a signed statement. The artifact was built by sbuild in unshare mode: a fresh copy of a recorded Ubuntu chroot tarball, as an unprivileged user, with the network switched off while the build ran, from sources whose digests were verified before the build started. That makes the build repeatable and its inputs checkable. It is still not L2 or L3: the build runs on the machine that holds the release key, it is started by the same operator who signs, and nothing here attests that the recipe in the source tree was unmodified. Read it as an accurate record of what went in, made hard to edit afterwards — not as proof of an untampered build."
}
