witness
Pluggable CLI tool for handling software artifact provenance
Pluggable CLI tool for handling software artifact provenance
To install this package, run one of the following:
Witness is a pluggable framework for software supply chain risk management that automates, normalizes, and verifies software artifact provenance.
Summary
Pluggable CLI tool for handling software artifact provenance
Last Updated
Jun 6, 2026 at 21:08
License
Apache-2.0
Supported Platforms
Home
https://witness.dev/GitHub Repository
https://github.com/in-toto/witnessDocumentation
https://witness.dev/docs/