SLSA Source Tool
Radar: Initial
Apache-2.0
A proof-of-concept implementation of the SLSA Source Track, attesting to source-side controls.
SLSA
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| SLSA | attests |
Using this from an agent
- Interfaces
cli- Emits
- in-toto-attestation
- Runtime
- Needs network Non-deterministic Read-only Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Experiment with attesting source-repository controls, not just build steps.
ci-pipeline
A proof of concept โ evaluate before depending on it.
- Website
- https://github.com/slsa-framework/source-tool
- Repository
- https://github.com/slsa-framework/source-tool
- License
- Apache-2.0 โ reported by the GitHub API, verified 2026-08-11
- Stars
- 18 ยท last commit 2026-08-10
Reading this as an agent? Don't scrape the page โ this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.