Generate SLSA build level 3 provenance as an in-toto attestation predicate

domain: slsa.dev · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Configure your build system to run inside a hardened, isolated build environment that satisfies SLSA L3 isolation requirements
  2. Instrument the build to record the exact source commit, build parameters, and environment variables as provenance metadata
  3. Produce an in-toto attestation envelope with the SLSA provenance predicate type and sign it with a key or OIDC-bound certificate
  4. Upload the signed attestation to a transparency log or attach it to the artifact in your registry
  5. Verify the attestation subject matches the artifact digest before promotion
  6. Publish provenance alongside the artifact so consumers can independently verify build authenticity

Known gotchas

Related routes

Generate and verify an in-toto attestation with a SLSA provenance predicate for a build artifact
security/compliance · 5 steps · unrated
Generate SLSA Build Level 3 provenance for a non-container build artifact using the slsa-github-generator generic workflow
github.com/slsa-framework/slsa-github-generator · 5 steps · unrated
Generate SLSA Build Level 3 provenance for a generic artifact using the slsa-github-generator generic reusable workflow in GitHub Actions
github.com/slsa-framework/slsa-github-generator · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans