Software Build Attestation Patents: Leaders & Trends 2026
A patent landscape review of software build attestation and CI/CD pipeline attestation covering 56 records, filing trends since 2015, leading assignees and the most-cited prior art.
Filing growth = 2021 (5 records) → 2024 (6); 2024 is the last year we treat as complete. Top-5 share = the 5 largest assignees ÷ all 56 records in scope (CR5), not the ranked leaders only.
What the software build attestation patent record shows
Software build attestation covers the mechanisms that produce and verify signed, tamper-evident metadata about how a software artifact was built — the build pipeline, source inputs and toolchain that produced it. This landscape draws on 56 published patent records filed between 2015 and the 2026 cut-off, spanning CI/CD pipeline attestation, container provenance tracking and related build-provenance claims. It is a young, still-forming field: the first records in scope appear only from 2017, and filing has never gone above single-digit growth from one year to the next until the 2022 peak.
The dataset draws from patent families where build, pipeline or continuous-integration language sits alongside attestation, provenance or signed-metadata claims — a definition wide enough to catch SLSA- and in-toto-style approaches without pulling in general software security filings. Reading it family by family, rather than by raw document count, gives a fairer picture of how much of this space a given filer actually occupies.
Filing trends and technology composition
Two views of the same 56 records: how filing has moved year over year, and which technical classes carry the claims.
A young field with an early peak
Filings rose from zero in 2017 to a peak of 11 records in 2022. Growth from 2021 to 2024 measured 5 to 6 records, a 20% rise over that three-year span. Counts for 2025 and 2026 are necessarily undercounted because publication trails filing by roughly 18 months — read the recent years as incomplete, not as a decline.
Publication lags filing by roughly 18 months, so 2025 onwards are still filling in. Growth rates on this page therefore end at 2024; running them to the last bar would understate the field.
Concentrated in two computing classes
G06F (electric digital data processing) appears in 67.9% of the 56 records and H04L (digital information transmission) in 55.4%, confirming that most build-attestation claims are drafted as computing and networking inventions rather than as business-process or AI claims. G06Q and G06N each cover a modest slice of records, while single filings touch additive manufacturing, building structures and non-electric control — signals of exploratory claims rather than an established sub-field.
Shares are the percentage of the 56 records in scope. A patent can carry several IPC classes, so the shares add up to more than 100%.
Go deeper on Software Supply-Chain Security: Software Build Attestation Patent Landscape with Eureka
This page is one run against one query. Ask Eureka your own question about software supply-chain security: software build attestation patent landscape and every answer comes back with the patent numbers behind it.
Try EurekaRepresentative filing and most-cited prior art
System and method for container provenance tracking
A system and computer-implemented method for container provenance tracking uses a build instruction file of a container image to output a new provenance document associated with the container image for distribution. For each file system layer of the container image specified in the build instruction file, an existing provenance document for the file system layer is inserted into the new provenance document. If there is no existing provenance document, information about each software component included in the file system layer is retrieved and inserted into the new provenance document.Filed by VMware, published 2020-06-11 — illustrates the layer-by-layer provenance assembly approach common to container-focused build attestation claims.


| # | Publication no. | Patent title | Citations |
|---|---|---|---|
| 1 | US20060236127A1 | Local secure service partitions for operating system security | 168 |
| 2 | US20180176229A1 | Decentralized automated software updates via blockchain | 142 |
| 3 | US20140222994A1 | Transparently tracking provenance information in distributed data systems | 27 |
| 4 | US20200183766A1 | System and method for container provenance tracking | 25 |
| 5 | US9276829B2 | Transparently tracking provenance information in distributed data systems | 25 |
| 6 | US20220391541A1 | Software provenance validation | 22 |
| 7 | US20210216636A1 | Determining Authenticity of Binary Images | 17 |
| 8 | WO2021097259A1 | Secure artificial intelligence model training and registration system | 12 |
| 9 | US20260073406A1 | Method and system for artificial intelligence based cryptocurrency regulatory analysis | 10 |
| 10 | US9282013B2 | Transparently tracking provenance information in distributed data systems | 9 |
Citation counts reflect influence within the searched corpus and skew toward older filings; they are not a measure of current commercial importance.
Each row carries its publication number; clicking a row searches Eureka by that number.
Put your own technology through the same analysis
Eureka on the web
When you want the answer in the next five minutes.
The agent works the prompt against patents and technical literature, citing every source.
Run your analysis now →MCP server & REST API
When it has to run inside your own pipeline.
Patent search, landscape analysis and assignee resolution as MCP tools. Drop them into any agent framework, or call REST directly.
Browse MCP servers →What the concentration and composition mean for filers
Three figures worth acting on before drafting or filing in this space.
The top of the field is tight
Five assignees hold 44.6% of all 56 records in scope, and the top ten hold 64.3%. A freedom-to-operate review in this space realistically starts with a short list of portfolios rather than a broad landscape scan.
Growth is real but modest
Filing rose from 5 records in 2021 to 6 in 2024, a 20% increase over three years, after peaking at 11 records in 2022. That peak-then-plateau pattern suggests an initial land-grab phase has already passed for some claim types.
Claims cluster in core computing classes
G06F and H04L together dominate the classification profile, meaning most inventions are framed as digital-processing or networked-transmission mechanisms. The handful of records touching additive manufacturing, construction and non-electric control point to attestation concepts being tested outside pure software contexts, but at very low volume so far.
Eureka can read the same corpus for gaps instead of for coverage: under-claimed branches adjacent to software supply-chain security: software build attestation patent landscape, with the prior art for and against each one.
Where to take this analysis
The dataset points to a few concrete next steps depending on what you are trying to decide.
Map claims against a specific build pipeline
Use the most-cited records and the representative filing as a starting set to check whether a planned attestation mechanism — container-layer provenance, signed CI metadata, or SLSA-style verification — reads on existing claims before drafting.
Explore claim scope in EurekaTrack the leading portfolios directly
With 44.6% of records held by five assignees, watching their continuation filings and newly published applications is a more efficient signal than scanning the full field.
Set up portfolio tracking in EurekaRevisit the trend once 2025-2026 fills in
Because publication lags filing by around 18 months, the most reliable read on whether the 2022 peak was a one-off will not be clear until later filings finish publishing.
Monitor filing trends in EurekaCommon questions about software build attestation patents
It is a patent claiming a mechanism that generates, signs or verifies metadata describing how a software artifact was built — the source inputs, build pipeline steps, or toolchain involved. This landscape defines it broadly enough to include CI/CD pipeline attestation, container provenance tracking, and SLSA- or in-toto-style approaches, provided the claims tie build or pipeline language to attestation, provenance or signed-metadata concepts. It excludes general software security patents that do not address build-time provenance specifically.
The assignee ranking for this dataset covers 29 companies, with the leader holding 8 of the 56 records in scope. Filing is concentrated rather than evenly spread: the top five assignees together hold 44.6% of all records, and the top ten hold 64.3%. That means due diligence in this space can focus on a relatively short list of portfolios rather than a long tail of single-filing entrants.
Filing activity rose from zero records in 2017 to a peak of 11 in 2022, then measured 5 records in 2021 growing to 6 by 2024 — a 20% increase over that three-year window. Figures for 2025 and 2026 are still incomplete because patent publication typically trails filing by about 18 months, so the apparent easing after 2022 should not yet be read as a genuine slowdown. A clearer picture will emerge once those later years finish publishing.
G06F (electric digital data processing) appears in 67.9% of the 56 records and H04L (digital information transmission) in 55.4%, making these the two dominant classification areas by a wide margin. Business-process claims under G06Q and AI-related claims under G06N each cover a smaller slice, around 10-13% of records. A handful of records extend attestation concepts into additive manufacturing, building structures and non-electric control, but each of those areas holds only a single filing so far, marking them as exploratory rather than established.
The classification data points to under-claimed adjacent branches: additive manufacturing, building structures, and non-electric control systems each carry only one record despite conceptual overlap with build-provenance tracking — for example, verifying the provenance of a 3D-printed part's build parameters the same way a software binary's build inputs are verified. Because the leading assignees are concentrated in core computing and networking claims (G06F, H04L), these adjacent framings remain comparatively open for a first-mover claim that ties attestation concepts to a non-software manufacturing or construction process.
Research Software Supply-Chain Security: Software Build Attestation Patent Landscape in depth with Eureka
Go past this page: query the whole software supply-chain security: software build attestation patent landscape corpus yourself, in your own scope.
Every answer comes back with patent numbers you can open.
Disclaimer. This page is generated from Patsnap Eureka data drawn from a limited snapshot of global patent and scientific-literature records, and is provided for general information and reference only.
Patent data carries inherent limitations: recent filings (typically the most recent 18–24 months) are under-counted due to standard publication lag; counts may be reported at either a patent-family or a patent-record basis and are not always directly comparable; classification, applicant-name, and citation data may contain errors, duplicates, or omissions; and the underlying search query defines and constrains the scope shown. As a result, the analysis may be incomplete or inaccurate and may not reflect the full technology landscape.
Nothing on this page constitutes an exhaustive prior-art, novelty, freedom-to-operate, or validity search, nor does it constitute legal, financial, investment, or professional advice, and it should not be relied upon as such. Any patent, commercial, or strategic decision should be verified independently and reviewed with qualified patent, legal, and domain professionals. Patsnap makes no warranties, express or implied, as to the accuracy, completeness, or fitness for any particular purpose of the information presented.