Automates, normalizes, and verifies software artifact provenance
Automates, normalizes, and verifies software artifact provenance
witness$ witness run -o artifact.json -- make build$ witness verify -artifactFile artifact.json -policyFile policy.json$ witness sign -artifactFile artifact.json -keyPath private.key