---
title: Provenance
description: Where a successful build’s image, SBOM and signed provenance are read back, and what each digest names.
type: how-to
product: builds
summary: Reading the SBOM and the signed provenance a build ended with.
updated: 2026-10-01
order: 1
---

<Callout tone="note" title="Today this runs on the management API">
The served build record is `GET /v1/deployments/builds/{id}`, which returns the build's image digest under `image.digest`. The `builds get` call below, with the SBOM and signed-provenance digests, belongs to the `builds` collection, which api.sylphx.com does not serve. See the [Builds quickstart](/docs/builds/quickstart).
</Callout>

A build that succeeds does not only produce an image. It ends with three
digests — the image, its SBOM and its signed provenance — and with the name of
one Artifact holding all three. Nothing extra is called to get them: they are
part of the build's own record.

## Read the build's output

The output is on the build, so the read is the ordinary one:

```bash
sylphx build builds get orgs/acme/projects/shop/builds/build
```

```bash
curl "https://api.sylphx.com/v1/orgs/acme/projects/shop/builds/build" \
  -H "Authorization: Bearer $SYLPHX_API_KEY"
```

```ts
const response = await sylphx.build.builds.get({ name: 'orgs/acme/projects/shop/builds/build' })
```

`status.output` is set when `status.state` is `succeeded`, and it carries
these five fields:

<PropertyTable
	properties={[
		{
			name: 'image',
			type: 'string',
			description: 'The image reference: registry.sylphx.net/path@sha256:hex.',
		},
		{
			name: 'image_digest',
			type: 'string',
			description: 'The image manifest digest.',
		},
		{
			name: 'sbom_digest',
			type: 'string',
			description: 'The SBOM Artifact digest.',
		},
		{
			name: 'provenance_digest',
			type: 'string',
			description: 'The signed SLSA provenance Artifact digest.',
		},
		{
			name: 'artifact',
			type: 'string',
			description: 'The Kernel Artifact holding the three.',
		},
	]}
/>

`image` is the reference to pull, and it is already by digest rather than by
tag: `registry.sylphx.net/<path>@sha256:<hex>`. The two Artifact digests are
the parts that make the image checkable rather than merely pullable — the SBOM
says what is inside it, and the signed provenance says what produced it.

## One Artifact, three digests

The three digests are named together by `output.artifact`, so a reader does
not have to correlate three records to answer one question. The Artifact is
where they live, and [the artifacts collection](/docs/api/artifacts) is what
reads it.

That is also why a build is worth reading after the fact. A build is immutable
once created, so the digest it ended with is the digest of the image it made —
a later build of the same repository produces its own record rather than
editing this one.

## When there is nothing to read

`status.output` is only present on a build that succeeded. A build that failed
carries `status.failure` instead, which is a typed reason — the source was
unavailable, the build itself errored, there was no capacity, the class was
not offered, signing was unavailable, or the build timed out.

A cancelled build publishes nothing at all. Its lease is released and no
Artifact is written, so there is no SBOM and no provenance to read for it.
That is the difference between a build that failed and a build that was
stopped: one has a reason, the other has no result.

<RelatedDocs
	links={[
		{
			href: '/docs/api/builds/get',
			label: 'get',
			description: 'Every field, the scope, and the examples.',
		},
		{
			href: '/docs/builds/quickstart',
			label: 'Builds quickstart',
			description: 'Create a build and follow it to its digests.',
		},
		{
			href: '/docs/builds/caches',
			label: 'Build caches',
			description: 'Why a cache changes a build’s speed and never its result.',
		},
	]}
/>
