{
  "node_id": "in-toto-attestation-framework-cncf",
  "title": "in-toto Attestation Framework (CNCF Graduated, Statement v1, Predicate Types: SLSA Provenance, VEX, SCAI, Vulnerability Scan, Test Result, Link, Layout; DSSE Signing)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-03",
  "bluf": "in-toto is the Cloud Native Computing Foundation (CNCF) graduated framework for supply chain integrity attestations. The in-toto Attestation Framework (at github.com/in-toto/attestation) provides a specification for generating verifiable claims about any aspect of how a piece of software is produced. It distinguishes between the Statement (the envelope, type 'https://in-toto.io/Statement/v1' that wraps the attestation, lists the subjects with artifact digests, and references a predicateType URI) and the Predicate (the payload metadata format vetted by in-toto maintainers). The vetted predicate types include SLSA Provenance v1.0 (build provenance), VEX (Vulnerability Exploitability Exchange) v1.0, SCAI (Supply Chain Attribute Integrity for arbitrary supply-chain claims), Vulnerability Scan, Test Result, Link (the original in-toto chain-of-custody link metadata), and Layout (the original in-toto supply-chain layout specification). Statements are signed using DSSE (Dead Simple Signing Envelope, the canonical envelope format for in-toto and SLSA attestations) which wraps the JSON-encoded Statement with one or more signatures from authorised signers; DSSE separates payload from signatures using a PAE (Pre-Authentication Encoding) to prevent ambiguity attacks. in-toto integrates with Sigstore's Cosign for OIDC-bound signing and with Rekor for transparency-log inclusion. CNCF graduation in 2023 elevated in-toto from incubation to the highest CNCF maturity tier alongside Kubernetes, Helm, and Prometheus. Language bindings exist for Go (most mature), Python, Rust, and Java. The original in-toto framework also defines a chain-of-custody model with software supply chain layouts, functionaries (authorised actors), steps with expected inputs/outputs, and link metadata recording each step's execution; this is the foundation on which the modern Attestation Framework is built.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "framework_basis",
      "key_institutions",
      "statement_envelope_v1",
      "vetted_predicate_types",
      "dsse_signing_envelope",
      "sigstore_cosign_integration",
      "slsa_provenance_predicate_integration",
      "original_in_toto_layout_link_model",
      "language_bindings",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "slsa-supply-chain-security-levels",
    "sigstore-cosign-fulcio-rekor-keyless-signing",
    "spdx-3-0-iso-iec-5962-2021-sbom-standard",
    "cyclonedx-1-7-owasp-ecma-sbom-standard"
  ],
  "primary_citations_count": 7
}