in-toto Attestation Specification
The in-toto specification defines the metadata format for recording software supply chain steps. It includes layout metadata that defines the expected steps and their authorized functionaries, and link metadata that records what actually happened at each step including materials consumed and products produced. Verification compares layouts against links to detect tampering.
Documentation
Specifications
Schemas & Data
JSONSchema
https://raw.githubusercontent.com/api-evangelist/in-toto/refs/heads/main/json-schema/in-toto-layout-schema.json
JSONSchema
https://raw.githubusercontent.com/api-evangelist/in-toto/refs/heads/main/json-schema/in-toto-link-schema.json
JSONSchema
https://raw.githubusercontent.com/api-evangelist/in-toto/refs/heads/main/json-schema/in-toto-attestation-schema.json