# Package Provenance ## Identification Package provenance records where a software package came from, how it was built and signed, what lineage it belongs to, and how it reached a particular device. ## Notebook evidence [[Scanned_20260730-1806]] traces visible app names to package IDs, developer handles, GitHub and Bitbucket projects, F-Droid records, forks, predecessor tools, embedded Dagger/JSR 305/GWT resources, carrier libraries, CyanogenMod-era applications, and developer domains. ## Provenance tuple Artifact hash · package ID · version/build · signer/certificate · installer/source · repository commit · dependency set · install path · device build · observation time. ## Evidentiary boundary A domain, source path, library resource, or adjacent developer name can suggest ancestry but does not by itself establish authorship, control, execution, or malicious behavior. ## Relationships [[Software Supply-Chain Provenance]] · [[Software Bill of Materials]] · [[Software Composition Analysis]] · [[Mobile Application Forensics]]. ## Scanned_20260730-1946 overlay The notebook adds two provenance paths. Pages 2 and 7 move from package managers into transitive libraries and daemons; pages 17–20 move from mobile package to decrypted binary, decompiled contents, runtime hooks, installer formats, embedded firmware, and upstream compression project. The source does not preserve exact package versions, hashes, signing certificates, repository commits, installers, or build attestations. These remain required before provenance can support integrity or attribution claims.