Witness
Apache-2.0
Wraps any build command and produces a signed in-toto attestation about what it observed — the materials, the products, and the environment.
in-totoSLSA
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
Using this from an agent
- Interfaces
clilibraryci-action- Install
-
go
github.com/in-toto/witness - Invoke
witness run -s <step-name> -o <attestation.json> -- <build-command>- Emits
- in-toto-attestation, json
- Runtime
- Runs offline Non-deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Add provenance to an existing build without restructuring the pipeline.
ci-pipeline
Wrapping the command is what makes this adoptable — the build does not have to change, it just gets observed.
Enforce that a build ran the steps a policy requires, in order.
ci-pipeline
- Website
- https://witness.dev
- Repository
- https://github.com/in-toto/witness
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-08-11
- Stars
- 544 · last commit 2026-08-10
- Matching caveat
- The name is an ordinary English word, so the job-corpus matcher cannot use it — sampled matches were "you'll witness first-hand", "Factory witness testing (FWT)" The bare name is blocked in the matcher, so this count reflects only qualified matches. Real adoption needs another source.
Reading this as an agent? Don't scrape the page — this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.