How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

SLSA Verifier

Radar: Initial Apache-2.0

Verifies SLSA provenance against expectations — that an artifact came from the source repository and builder it claims.

SLSA

Specifications it implements

What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.

StandardRoleWhat that means
SLSA verifies
Using this from an agent
Interfaces
clilibraryci-action
Install
go github.com/slsa-framework/slsa-verifier/v2/cli/slsa-verifier
Invoke
slsa-verifier verify-artifact <artifact> --provenance-path <provenance> --source-uri <repo>
Consumes
in-toto-attestation
Emits
json, text
Runtime
Runs offline Deterministic Read-only No credentials

Where it applies

Jobs this tool actually does, and the surface each one is exercised on.

Check the provenance of a dependency before installing it.
coding-agentci-pipeline

The consumer side, and the one that actually reduces risk. Generating provenance nobody verifies changes nothing.

Website
https://github.com/slsa-framework/slsa-verifier
Repository
https://github.com/slsa-framework/slsa-verifier
License
Apache-2.0 — reported by the GitHub API, verified 2026-08-11
Stars
344 · last commit 2026-08-07
Reading this as an agent? Don't scrape the page — this entry is published as structured data at /tools.json, against the tool.schema.json schema, using the roles.json vocabulary. Start at /llms.txt.
arrow_back All tools by adoption