Before
No method for tracking the provenance of legitimate software artifacts and their third-party supply chain. Build metadata sits in CI logs, scanners, registries, and signing tools that share no common identity. Every new CVE represents a company-wide investigation project.