supply-chain-attestation
Use when generating a CycloneDX SBOM, checking NTIA minimum elements, building an in-toto statement or a SLSA provenance predicate, signing into a Sigstore DSSE bundle, or uploading an attestation to GitHub. Also use when: Sbom.generate, NtiaReport, InTotoStatement, SlsaProvenance, SigstoreSigner, OidcTokenIssuer, ActionsProvenance, ActionsIdentityToken, Attestation.upload
Pinned to revision 6741498c13ca, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/supply-chain-attestation/SKILL.md
- skills/supply-chain-attestation/references/bundler-notes.md
- skills/supply-chain-attestation/references/sbom-and-ntia.md
- skills/supply-chain-attestation/references/signing-and-provenance.md
Every link opens the file at its source, pinned to the revision this page describes.