AttestChain · v1.0 — slsa + sigstore + in-toto
offline · zero telemetry

Supply-Chain Attestation Chain

22 build artifacts (containers + npm + pip + binaries) with SLSA v1.0 attestation chain. Per artifact: SLSA level, Sigstore signature, in-toto provenance, SBOM (CycloneDX 1.6), build-system attestation, source provenance, runtime verification. Surfaces 4 SLSA Level 1 + 2 unsigned releases.

artifacts
0
SLSA L3+
0
SLSA L1 (no prov)
0
unsigned
0
SBOM coverage
0%
Select an artifact to inspect its attestation chain.