Software Supply Chain

in-toto

in-toto Attestation Framework

Foundation Global CNCF Since 2016

A framework for cryptographically verifying that every step of a software supply chain was carried out by the intended party, in the intended order, on the intended materials.

Its attestation format is the substrate SLSA provenance is carried in, so adopt it as plumbing rather than as a programme of its own.

At a glance

Category
Software Supply Chain
Jurisdiction
Global
Governance
CNCF
Status
CNCF graduated project (2025); in-toto Attestation Framework v1.0
First released
2016

Links

Related frameworks

Other entries under Software Supply Chain.

See in-toto in context

Open the interactive Data Landscape for Regulation to compare in-toto against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.