SLSA Verifier
Radar: Initial
Apache-2.0
Verifies SLSA provenance against expectations — that an artifact came from the source repository and builder it claims.
SLSA
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| SLSA | verifies |
Using this from an agent
- Interfaces
clilibraryci-action- Install
-
go
github.com/slsa-framework/slsa-verifier/v2/cli/slsa-verifier - Invoke
slsa-verifier verify-artifact <artifact> --provenance-path <provenance> --source-uri <repo>- Consumes
- in-toto-attestation
- Emits
- json, text
- Runtime
- Runs offline Deterministic Read-only No credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Check the provenance of a dependency before installing it.
coding-agentci-pipeline
The consumer side, and the one that actually reduces risk. Generating provenance nobody verifies changes nothing.
- Website
- https://github.com/slsa-framework/slsa-verifier
- Repository
- https://github.com/slsa-framework/slsa-verifier
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-08-11
- Stars
- 344 · last commit 2026-08-07
Reading this as an agent? Don't scrape the page — this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.