This document discusses auditing and maintaining provenance in software packages. It presents CDE-SP, an enhancement to the CDE system that captures additional details about software dependencies to enable attribution of authorship as software packages are combined and merged into pipelines. CDE-SP uses a lightweight key-value storage system to store provenance data within packages and allows provenance queries to determine package dependencies and validate authorship as packages are combined. Experiments show the overhead of CDE-SP is negligible for audit performance, storage size, and execution compared to the original CDE system.