SLSA Provenance Policy Auditor avatar

SLSA Provenance Policy Auditor

Pricing

from $6.00 / 1,000 slsa provenance audits

Go to Apify Store
SLSA Provenance Policy Auditor

SLSA Provenance Policy Auditor

Audit in-toto SLSA provenance for subject digests, builder and build type allowlists, source expectations, timestamps and DSSE envelope presence.

Pricing

from $6.00 / 1,000 slsa provenance audits

Rating

0.0

(0)

Developer

Q Services

Q Services

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

a month ago

Last modified

Categories

Share

Audit in-toto SLSA provenance statements and DSSE envelopes against explicit artifact, builder, build-type and source expectations. The Actor validates structure and policy locally and never downloads artifacts or dependencies.

Important boundary

The Actor reports whether a DSSE signature is present but does not verify its cryptographic trust chain. cryptographicSignatureVerified is always false. Use a signer-specific verifier alongside this structural policy gate.

Input

Each item in provenances can include content, expectedSubjects, allowedBuilderIds, allowedBuildTypes, allowedSourcePrefixes, requireEnvelope and requireSignature.

Pricing

Pay per event: one actor-start event per run and one dataset-item event per completed provenance audit.