Skip to content

Slot: guacUri

URI to query the GUAC (Graph for Understanding Artifact Composition) instance for dependency and provenance graph data related to this artifact (e.g., "https://guac.example.com/api/v0/artifact/sha256:..."). GUAC is an OpenSSF project that ingests SLSA provenance, SBOMs, and vulnerability data to produce a queryable supply chain graph. Providing this URI enables consumers to retrieve the full transitive dependency graph and associated risk signals without reprocessing all upstream attestations.

URI: slsa:guacUri Alias: guacUri

Properties

Type and Range

Property Value
Range String

Cardinality and Requirements

Property Value

In Subsets

Identifier and Mapping Information

Schema Source

  • from schema: https://w3id.org/lmodel/slsa

Mappings

Mapping Type Mapped Value
self slsa:guacUri
native slsa:guacUri

LinkML Source

name: guacUri
description: URI to query the GUAC (Graph for Understanding Artifact Composition)
  instance for dependency and provenance graph data related to this artifact (e.g.,
  "https://guac.example.com/api/v0/artifact/sha256:..."). GUAC is an OpenSSF project
  that ingests SLSA provenance, SBOMs, and vulnerability data to produce a queryable
  supply chain graph. Providing this URI enables consumers to retrieve the full transitive
  dependency graph and associated risk signals without reprocessing all upstream attestations.
in_subset:
- slsa_build_track
- slsa_dependency_track
- slsa_ssf
from_schema: https://w3id.org/lmodel/slsa
rank: 1000
alias: guacUri
range: string