SLSA Provenance Policy Auditor
Pricing
from $6.00 / 1,000 slsa provenance audits
SLSA Provenance Policy Auditor
Audit in-toto SLSA provenance for subject digests, builder and build type allowlists, source expectations, timestamps and DSSE envelope presence.
Pricing
from $6.00 / 1,000 slsa provenance audits
Rating
0.0
(0)
Developer
Q Services
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
a month ago
Last modified
Categories
Share
Audit in-toto SLSA provenance statements and DSSE envelopes against explicit artifact, builder, build-type and source expectations. The Actor validates structure and policy locally and never downloads artifacts or dependencies.
Important boundary
The Actor reports whether a DSSE signature is present but does not verify its
cryptographic trust chain. cryptographicSignatureVerified is always false.
Use a signer-specific verifier alongside this structural policy gate.
Input
Each item in provenances can include content, expectedSubjects,
allowedBuilderIds, allowedBuildTypes, allowedSourcePrefixes,
requireEnvelope and requireSignature.
Pricing
Pay per event: one actor-start event per run and one dataset-item event per
completed provenance audit.
