Build transparency now includes RPM package provenance, signed SPDX JSON SBOMs for architecture-specific image digests, and generated GitHub Release changelogs for the stable, testing, and lts streams.

These serve different purposes. Build artifacts provide a short-lived package provenance report; signed SBOMs provide a durable inventory attached to the published image digest.

Read the current inspection instructions.