Timeline and lead time
Read a change's checks, reports, bypasses and deployments in order.
Open a change from Provenance, or follow Open in Provenance from a run, deployment or pull request. The detail page shows the verdict, landed commits, bypasses and timeline.
Read the evidence
The timeline records available first commits and pull request updates, gate evaluations, reviews, test counts, coverage, scans, software bills of materials, build provenance, finding carry-over, pipeline results, compliance decisions and deployments. Events link to their source when a link is available.
A missing fact is not a passing check. Not reported means the provider or source did not supply that fact. Open Landed commits to see how each commit was matched to checked code and why any commit remains unverified.
Bypasses include their kind, actor when known, time and evidence. Confirmed by means the provider reported the bypass; Inferred from the push means Prodgator inferred it from the available facts. See provider coverage.
The Audit event link opens Organization > Audit Log for members who can read the audit log and whose plan includes it. It opens the linked audit entry.
Lead time
Lead time runs from the first known commit to the first recorded successful deployment containing the change in a protected environment. If the first commit's time is missing, it starts at pull request opening, then at landing if the opening time is also missing. The page names the start used and the environment reached.
A later deployment can include the change through a descendant commit. Prodgator must be able to confirm that the deployment contains the landed commits. Failed deployments and deployments to environments without gate coverage do not establish this milestone. If no qualifying deployment has been recorded, the milestone and lead time remain unreported.
Record integrity and retention
Record intact means the retained timeline events pass the stored hash-chain check. Record changed after writing identifies an event where that check failed. Ask your Org admin to investigate an integrity warning before relying on the record.
Older events can expire under your plan's retention. Earlier events expired means verification starts at the retained portion; expiration alone is not evidence that someone changed the record. A hash-checked timeline is not yet a signed attestation.