URI or name of the tool used to cryptographically sign the artifact or attestation (e.g., "https://github.com/sigstore/cosign", "https://github.com/notaryproject/notation"). In the SSF reference architecture the Signing Service layer is distinct from the Build Service; recording the signing tool enables verifiers to select the matching verification workflow. For Sigstore keyless signing the value should be the Cosign release URI.
URI: slsa:signingTool
Alias: signingTool
Applicable Classes
Properties
Type and Range
Cardinality and Requirements
In Subsets
Schema Source
- from schema: https://w3id.org/lmodel/slsa
Mappings
| Mapping Type |
Mapped Value |
| self |
slsa:signingTool |
| native |
slsa:signingTool |
LinkML Source
name: signingTool
description: URI or name of the tool used to cryptographically sign the artifact or
attestation (e.g., "https://github.com/sigstore/cosign", "https://github.com/notaryproject/notation").
In the SSF reference architecture the Signing Service layer is distinct from the
Build Service; recording the signing tool enables verifiers to select the matching
verification workflow. For Sigstore keyless signing the value should be the Cosign
release URI.
in_subset:
- slsa_build_track
- slsa_source_track
- slsa_ssf
from_schema: https://w3id.org/lmodel/slsa
rank: 1000
alias: signingTool
domain_of:
- Statement
range: string