Witness is a pluggable framework for supply chain security
Witness prevents tampering of build materials and verifies the integrity of the build process from source to target. It works by wrapping commands executed in a continuous integration process. Its attestation system is pluggable and offers support out of the box for most major CI and infrastructure providers. Verification of Witness metadata and a secure PKI distribution system will mitigate against many supply chain attack vectors.
Records secure hashes of materials, artifacts, and events occurring during the CI process
Integrations with cloud identity services
Keyless signing with SPIFFE/SPIRE
Support for uploading attestation evidence to rekor server (sigstore)