Sigstore - Software Artifact Signing and Verification
Sigstore: Verification and Policy Enforcement

Sigstore - Software Artifact Signing and Verification SIGSTORE-VER-2: Supply Chain Attestation

Support in-toto attestation format for software supply chain metadata and provenance verification

Other controls in Sigstore: Verification and Policy Enforcement

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.