Skip to content

Security

Provenance attestation

Quick answer

A provenance attestation is a signed statement describing how an artefact was built, including source, builder and inputs.

A provenance attestation is a signed statement describing how an artefact was built, including source, builder and inputs.

Why it matters

It is what lets a consumer verify that an image really came from the repository and workflow it claims. GitHub can generate SLSA-compatible attestations natively.

Your next build could be twice as fast, at half the price

Start free. Migrating away is the same one line, and we publish that diff too.