Slot: guacUri
URI to query the GUAC (Graph for Understanding Artifact Composition) instance for dependency and provenance graph data related to this artifact (e.g., "https://guac.example.com/api/v0/artifact/sha256:..."). GUAC is an OpenSSF project that ingests SLSA provenance, SBOMs, and vulnerability data to produce a queryable supply chain graph. Providing this URI enables consumers to retrieve the full transitive dependency graph and associated risk signals without reprocessing all upstream attestations.
URI: slsa:guacUri
Alias: guacUri
Properties
Type and Range
Cardinality and Requirements
In Subsets
Schema Source
- from schema: https://w3id.org/lmodel/slsa
Mappings
| Mapping Type |
Mapped Value |
| self |
slsa:guacUri |
| native |
slsa:guacUri |
LinkML Source
name: guacUri
description: URI to query the GUAC (Graph for Understanding Artifact Composition)
instance for dependency and provenance graph data related to this artifact (e.g.,
"https://guac.example.com/api/v0/artifact/sha256:..."). GUAC is an OpenSSF project
that ingests SLSA provenance, SBOMs, and vulnerability data to produce a queryable
supply chain graph. Providing this URI enables consumers to retrieve the full transitive
dependency graph and associated risk signals without reprocessing all upstream attestations.
in_subset:
- slsa_build_track
- slsa_dependency_track
- slsa_ssf
from_schema: https://w3id.org/lmodel/slsa
rank: 1000
alias: guacUri
range: string