# Component Provenance in NXRM

**URL:** <https://community.sonatype.com/t/component-provenance-in-nxrm/4909>\
**Category:** Sonatype Nexus Repository\
**Tags:** documentation, feature-request\
**Created:** [September 10, 2020, 11:41am UTC](https://community.sonatype.com/t/component-provenance-in-nxrm/4909 "2020-09-10T11:41:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![msymons](https://avatars.discourse-cdn.com/v4/letter/m/a6a055/32.png) [@msymons](https://community.sonatype.com/u/msymons)\
**Post date:** [September 10, 2020, 11:41am UTC](https://community.sonatype.com/t/component-provenance-in-nxrm/4909/1 "2020-09-10T11:41:42Z")

</div>

Examining component information within Nexus Repository Manager OSS v3.27.0, I see `Containing repo` listed under Summary and `Provenance` listed under Attributes. For every component I have inspected the `Provenance` always says “hashes\_not\_verified”.

Provenance is not documented. It should be. What do you mean when you say “Provenance”? Also, why are hashes not verified and what can I do to address that? If there answer is “all covered by NXRM Pro” then that is a important for documentation (and also helps your marketing 😀)

My understanding of Provenance is that it all about origin. ie, `Containing repo` (see above) is actually part of Provenance. However Provenance also covers who the manufacturer is… the person, organization, or GitHub project that manufactured the component. None of this is provided.

Hash validation can be a part of Provenance, but is really more to do with Pedigree (the individual DNA of specific components).

---

<div class="post-metadata">

**Author:** ![msymons](https://avatars.discourse-cdn.com/v4/letter/m/a6a055/32.png) [@msymons](https://community.sonatype.com/u/msymons)\
**Post date:** [September 26, 2020, 4:39pm UTC](https://community.sonatype.com/t/component-provenance-in-nxrm/4909/2 "2020-09-26T16:39:23Z")

</div>

Anything? Is it not a defect to have areas of functionality which are undocumented?

---

<div class="post-metadata">

**Author:** ![mprescott](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/mprescott/32/178_2.png) [@mprescott](https://community.sonatype.com/u/mprescott)\
**Post date:** [September 23, 2021, 4:57pm UTC](https://community.sonatype.com/t/component-provenance-in-nxrm/4909/3 "2021-09-23T16:57:11Z")

</div>

@msymons Thanks for raising this - yes, Provenance definitely is an area that could use a little love. What would be most valuable for you to see here? I get that it’s confusing and partial in its current state, if we removed it for now would be an improvement, or did you go to this looking for information that you need?
