Skip to content

Slot: sigstoreLogEntry

URI of the Rekor transparency log entry recording this attestation or artifact signature (e.g., "https://rekor.sigstore.dev/api/v1/log/entries/24296fb..."). The Rekor log provides an immutable, auditable record of signing events that underpins Sigstore keyless signing. Verifiers can fetch this entry to confirm the cryptographic signature was recorded in the public-good log and obtain the signing certificate chain issued by Fulcio. Recording this URI enables offline and third-party verification without requiring direct access to the original signing key.

URI: slsa:sigstoreLogEntry Alias: sigstoreLogEntry

Applicable Classes

Name Description Modifies Slot
SourceProvenanceAttestation An attestation describing how a source revision came to exist: where it was h... no
Statement The middle layer of an in-toto software attestation (Statement v1) no
VerificationSummaryAttestation An attestation predicate (predicateType "https://slsa no
BuildEnvironmentAttestation An attestation describing the integrity of a build environment at the time a ... no
BuildProvenance An attestation predicate (predicateType "https://slsa no

Properties

Type and Range

Property Value
Range String
Domain Of Statement

Cardinality and Requirements

Property Value

In Subsets

Identifier and Mapping Information

Schema Source

  • from schema: https://w3id.org/lmodel/slsa

Mappings

Mapping Type Mapped Value
self slsa:sigstoreLogEntry
native slsa:sigstoreLogEntry

LinkML Source

name: sigstoreLogEntry
description: URI of the Rekor transparency log entry recording this attestation or
  artifact signature (e.g., "https://rekor.sigstore.dev/api/v1/log/entries/24296fb...").
  The Rekor log provides an immutable, auditable record of signing events that underpins
  Sigstore keyless signing. Verifiers can fetch this entry to confirm the cryptographic
  signature was recorded in the public-good log and obtain the signing certificate
  chain issued by Fulcio. Recording this URI enables offline and third-party verification
  without requiring direct access to the original signing key.
in_subset:
- slsa_build_track
- slsa_source_track
- slsa_ssf
from_schema: https://w3id.org/lmodel/slsa
rank: 1000
alias: sigstoreLogEntry
domain_of:
- Statement
range: string