{
 "_type": "https://in-toto.io/Statement/v1",
 "subject": [
  {
   "name": "proftpd-mod-crypto_1.3.9d~dfsg-1~corecp10_amd64.deb",
   "digest": {
    "sha512": "c3822b50b821cf2e460ed118b8d74917ab9c45e0b44292b2f937b5e4e30fbf932eb3058451c15f705cfe1f8008907b83b270436e249b116adef8a8c18fda2791",
    "sha256": "bea8a39b713319726db497beb3615e36364e2545202dcf0a2f6d5d60de873889"
   }
  }
 ],
 "predicateType": "https://slsa.dev/provenance/v1",
 "predicate": {
  "buildDefinition": {
   "buildType": "https://corecp.dev/build/sbuild/v1",
   "externalParameters": {
    "package": "proftpd-mod-crypto",
    "version": "1.3.9d~dfsg-1~corecp10",
    "architecture": "amd64",
    "buildScript": "scripts/component-build",
    "sourceCommit": null,
    "sourceCommitNote": "unknown: this build ran from a source tree with no git history (the build server holds an rsync copy), and no caller passed CORECP_SOURCE_COMMIT",
    "recipe": "component-build"
   },
   "internalParameters": {
    "toolchain": {
     "binutils": "2.46-3ubuntu2",
     "dpkg-dev": "1.23.7ubuntu1",
     "g++-15": "15.2.0-16ubuntu1",
     "gcc-15": "15.2.0-16ubuntu1",
     "libc6-dev": "2.43-2ubuntu2.4",
     "make": "4.4.1-3"
    },
    "environment": {
     "mode": "sbuild-unshare",
     "network": "disabled during the build (sbuild enable_network=0)",
     "chrootTarballSha256": "83ed65faa9a093e4a8dbc8f95453aecfffc39fc4d19b626fdc737096eb0d6f78"
    }
   },
   "resolvedDependencies": [
    {
     "name": "proftpd-dfsg_1.3.9d~dfsg-1.debian.tar.xz",
     "uri": "file:///srv/corecp/build/e2e-bouwstraat-fr6cb2221540/fixture/archive/pool/main/p/proftpd-dfsg/proftpd-dfsg_1.3.9d~dfsg-1.debian.tar.xz",
     "digest": {
      "sha256": "da05beed96c7036b6b2639d0a471d0955b10385dbeecfc3faca0a17da5124b4f"
     },
     "annotations": {
      "verified": "SHA-256 from the archive's signed source index"
     }
    },
    {
     "name": "proftpd-dfsg_1.3.9d~dfsg-1.dsc",
     "uri": "file:///srv/corecp/build/e2e-bouwstraat-fr6cb2221540/fixture/archive/pool/main/p/proftpd-dfsg/proftpd-dfsg_1.3.9d~dfsg-1.dsc",
     "digest": {
      "sha256": "e58396555c8a3cc69faf04e2f57b3c333f65c7ed08d5216c344b1e3e97d67c8f"
     },
     "annotations": {
      "verified": "SHA-256 from the archive's signed source index"
     }
    },
    {
     "name": "proftpd-dfsg_1.3.9d~dfsg.orig.tar.gz",
     "uri": "file:///srv/corecp/build/e2e-bouwstraat-fr6cb2221540/fixture/archive/pool/main/p/proftpd-dfsg/proftpd-dfsg_1.3.9d~dfsg.orig.tar.gz",
     "digest": {
      "sha256": "d4a14ce8c8ade1e30e84bef3fd5077263f23f20d6b8bdf8e2a03bf804d5e2677"
     },
     "annotations": {
      "verified": "SHA-256 from the archive's signed source index"
     }
    }
   ]
  },
  "runDetails": {
   "builder": {
    "id": "https://build.corecp.dev/corecp-build",
    "builderDependencies": [
     {
      "name": "resolute-amd64.tar.zst",
      "digest": {
       "sha256": "83ed65faa9a093e4a8dbc8f95453aecfffc39fc4d19b626fdc737096eb0d6f78"
      }
     },
     {
      "name": "proftpd-dfsg_1.3.9d~dfsg-1~corecp10_amd64.buildinfo",
      "digest": {
       "sha256": "bf00bcf124f4adb0e9b25e3b4a9ec6ae17af80f0310a5c95f035fd3adbd7bc1f"
      },
      "annotations": {
       "installedBuildDepends": 216
      }
     }
    ]
   },
   "metadata": {
    "invocationId": "proftpd-mod-crypto-1.3.9d~dfsg-1~corecp10-bea8a39b71331972",
    "startedOn": "2026-09-24T03:53:42Z",
    "finishedOn": "2026-09-24T03:53:42Z"
   }
  }
 },
 "_note": "SLSA Build L1 with a signed statement. The artifact was built by sbuild in unshare mode: a fresh copy of a recorded Ubuntu chroot tarball, as an unprivileged user, with the network switched off while the build ran, from sources whose digests were verified before the build started. That makes the build repeatable and its inputs checkable. It is still not L2 or L3: the build runs on the machine that holds the release key, it is started by the same operator who signs, and nothing here attests that the recipe in the source tree was unmodified. Read it as an accurate record of what went in, made hard to edit afterwards — not as proof of an untampered build."
}
