Policy Types
Develocity Provenance Governor supports the following policy types:
| Policy Kind | Description |
|---|---|
|
Enforce specific build tool and version usage |
|
Control Java toolchain (JDK version/vendor) requirements |
|
Restrict dependency resolution sources |
|
Allow or block specific dependencies |
|
Enforce artifact promotion workflows |
|
Verify required attestation types exist |
|
Validate attestation signatures |
|
Evaluate VSA verification results |
|
Score dependency health using SLO-based vulnerability and upgrade compliance |