Reference — generated from the toolkit
Source of truth: toolkit/templates/release-evidence-pack.md. Edit it there; this page is regenerated on build.
Release evidence pack — {product} {version}
- Product / version: … Release date: {YYYY-MM-DD} Assembled by: pipeline
Contents
| Item | Source | Status |
|---|---|---|
| SBOM (CycloneDX) | build | auto |
| Gate results (merge + production readiness) | CI/CD | auto |
| Test coverage + mutation summary | CI | auto |
| Threat-model reference | Design | link |
| DPIA status | compliance pack | link |
| Human authorisations (deploy, migrations) | provenance trail | auto |
| Provenance summary (agent/model/prompt per change) | provenance trail | auto |
How it's used
Handed to a client's procurement / vendor-risk team on request, or to an auditor. Because it assembles automatically from the AI provenance trail and the security gates, it's always complete and costs nothing per release.