---
title: "Verifying signed artifacts in a delivery pipeline"
description: "How can you reject an artifact with invalid signature or provenance?"
status: "coming-soon"
language: "en"
canonical: "https://bulnik.dev/en/articles/topics/T49.10/"
topicId: "T49.10"
---

> Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

## The question

How can you reject an artifact with invalid signature or provenance?

## What we will work through

Reject an artifact with invalid signature or provenance.

## Before you begin

Previously covered: SBOMs and dependency provenance; Certificates, keys, and trust chains.

- [SBOMs and dependency provenance](/en/articles/topics/T49.09/)
- [Certificates, keys, and trust chains](/en/articles/topics/T49.01/)
