Use the Evidence tab to view the evidence associated with an application version in tabular form. Evidence is a central component of AppTrust, as it provides an immutable audit trail of the actions and operations performed on the application version throughout its lifecycle.

To view application version evidence:

  1. In the JFrog Platform, go to AppTrust > Applications.
  2. In the Applications table, click the name of the relevant application.
  3. In the sidebar, click Lifecycle. The Stages Board tab appears.
  4. In the Stages Board, click the relevant application version to drill down into the version.
  5. Above the version timeline, click the Evidence tab.
App-version_Evidence-tab.png

The table of Related Evidence Files includes the following information:

  • Verified: Whether the evidence signature has been verified using the public key uploaded to Artifactory.
  • Evidence type: The evidence type, for example, evidence about a promotion to a lifecycle stage or an SBOM with the contents of the evidence subject.
  • Time: The timestamp of when the evidence was created.
  • Created By: The user who created the evidence.

Click a table row to view evidence details. For more information, see View the Evidence Predicate.

Download Evidence

To download evidence to your local system, go to the action menu at the end of the table row and click Download Evidence.

App-version_download-evidence-option.png

Did this page help you?