Define and verify an in-toto software supply chain layout with materials and products

domain: in-toto.io · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Define a layout file that names each functionary (step owner), specifies expected materials and products for each step, and sets inspection rules
  2. Sign the layout with the project owner key and distribute the public key to verifiers
  3. Instrument each pipeline step to produce a signed link metadata file recording actual materials consumed and products generated
  4. Collect all link files at the end of the pipeline
  5. Run in-toto verify with the layout and the collected link files to confirm the supply chain executed as declared
  6. Fail the release if verification exits non-zero or if any inspection rule is violated

Known gotchas

Related routes

Define and verify an in-toto supply chain layout to validate pipeline step attestations
github.com/in-toto/attestation · 6 steps · unrated
Define an in-toto link metadata chain for a software supply chain using the in-toto Python tools to sign each step (clone, build, test) and verify the final product
in-toto.io · 5 steps · unrated
Use the in-toto Python library to create and sign link metadata for each step in a software supply chain
in-toto.io · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans