in-toto attestation
also: attestation, in-toto statement
A cryptographically signed record that documents what happened during a step of a software supply chain, proving who performed an action and what the inputs and outputs were.
in-toto attestation is a standardized format for capturing evidence about software build and deployment activities. Each attestation is signed by a key that only the performer should possess, creating a tamper-proof record of what occurred.
An attestation documents: the materials (input files), the products (output files), the environment (tool versions, working directory), and the byproducts (return codes, stdout/stderr). For example, a build attestation records which source files were compiled, what binaries were produced, and the exact compiler command that was run.
Multiple attestations are linked together in an in-toto layout, forming a chain of evidence across the entire supply chain. This allows you to verify that authorized steps happened in the correct order with expected artifacts, detecting if malicious actors injected code or skipped security checks.