Witness
Wraps any build command and produces a signed in-toto attestation about what it observed — the materials, the products, and the environment.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
- Interfaces
clilibraryci-action- Install
-
go
github.com/in-toto/witness - Invoke
witness run -s <step-name> -o <attestation.json> -- <build-command>- Emits
- in-toto-attestation, json
- Runtime
- Runs offline Non-deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Wrapping the command is what makes this adoptable — the build does not have to change, it just gets observed.
- Website
- https://witness.dev
- Repository
- https://github.com/in-toto/witness
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 546 · last commit 2026-09-16
- Matching caveat
- The name is an ordinary English word, so the job-corpus matcher cannot use it — sampled matches were "you'll witness first-hand", "Factory witness testing (FWT)" The bare name is blocked in the matcher, so this count reflects only qualified matches. Real adoption needs another source.
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.