Software Supply Chain
in-toto
in-toto Attestation Framework
Foundation
Global
CNCF
Since 2016
A framework for cryptographically verifying that every step of a software supply chain was carried out by the intended party, in the intended order, on the intended materials.
Its attestation format is the substrate SLSA provenance is carried in, so adopt it as plumbing rather than as a programme of its own.
At a glance
- Category
- Software Supply Chain
- Jurisdiction
- Global
- Governance
- CNCF
- Status
- CNCF graduated project (2025); in-toto Attestation Framework v1.0
- First released
- 2016
Links
Related frameworks
Other entries under Software Supply Chain.
- SPDX: System Package Data Exchange
- CycloneDX: CycloneDX Bill of Materials
- SLSA: Supply-chain Levels for Software Artifacts
- Sigstore
See in-toto in context
Open the interactive Data Landscape for Regulation to compare in-toto against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.