SLSA Verifier
Verifies SLSA provenance against expectations — that an artifact came from the source repository and builder it claims.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| SLSA | verifies |
- Interfaces
clilibraryci-action- Install
-
go
github.com/slsa-framework/slsa-verifier/v2/cli/slsa-verifier - Invoke
slsa-verifier verify-artifact <artifact> --provenance-path <provenance> --source-uri <repo>- Consumes
- in-toto-attestation
- Emits
- json, text
- Runtime
- Runs offline Deterministic Read-only No credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
The consumer side, and the one that actually reduces risk. Generating provenance nobody verifies changes nothing.
- Website
- https://github.com/slsa-framework/slsa-verifier
- Repository
- https://github.com/slsa-framework/slsa-verifier
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 344 · last commit 2026-08-07
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.