# Witness [](https://pkg.go.dev/github.com/in-toto/witness) [](https://goreportcard.com/report/github.com/in-toto/witness) [](https://www.bestpractices.dev/projects/8164) [](https://securityscorecards.dev/viewer/?uri=github.com/in-toto/witness) [](https://app.fossa.com/projects/custom%2B41709%2Fgithub.com%2Fin-toto%2Fwitness?ref=badge_shield&issueType=license) Witness originated at **[TestifySec](https://www.testifysec.com)** and was later donated to the CNCF in-toto ecosystem. It is now maintained by the open community.
### What does Witness do?
✏️ **Attests** - Witness is a dynamic CLI tool that integrates into pipelines and infrastructure to create an
audit trail for your software's entire journey through the software development lifecycle (SDLC) using the in-toto specification.
**🧐 Verifies** - Witness also features its own policy engine with embedded support for OPA Rego, so you can
ensure that your software was handled safely from source to deployment.
### What can you do with Witness?
- Verify how your software was produced and what tools were used
- Ensure that each step of the supply chain was completed by authorized users and machines
- Detect potential tampering or malicious activity
- Distribute attestations and policy across air gaps
### Key Features
- Integrations with GitLab, GitHub, AWS, and GCP.
- Designed to run in both containerized and non-containerized environments **without** elevated privileges.
- Implements the in-toto specification (including ITE-5, ITE-6 and ITE-7)
- An embedded OPA Rego policy engine for policy enforcement
- Keyless signing with Sigstore and SPIFFE/SPIRE
- Integration with RFC3161 compatible timestamp authorities
- Process tracing and process tampering prevention (Experimental)
- Attestation storage with [Archivista](https://github.com/in-toto/archivista)
### Demo
![Demo][demo]
## Quick Start
### Installation
To install Witness, all you will need is the Witness binary. You can download this from the [releases](https://github.com/in-toto/witness/releases) page or use the install script to download the
latest release:
```
bash <(curl -s https://raw.githubusercontent.com/in-toto/witness/main/install-witness.sh)
```
If you want install it manually and verify its integrity follow the instructions in the [INSTALL.md](./INSTALL.md).
### Tutorials
Check out our Tutorials:
- [Getting Started](docs/tutorials/getting-started.md)
- [Verify an Artifact Policy](docs/tutorials/artifact-policy.md)
- [Using Fulcio as a Key Provider](docs/tutorials/artifact-policy.md)
## Media
Check out some of the content out in the wild that gives more detail on how the project can be used.
##### [Blog/Video - Generating and Verifying Attestations With Witness](https://www.testifysec.com/blog/attestations-with-witness/)
##### [Blog - What is a supply chain attestation, and why do I need it?](https://www.testifysec.com/blog/what-is-a-supply-chain-attestation/)
##### [Talk - Securing the Software Supply Chain with the in-toto & SPIRE projects](https://www.youtube.com/watch?v=4lFbdkB62QI)
##### [Talk - Securing the Software Supply Chain with SBOM and Attestation](https://www.youtube.com/watch?v=wX6aTZfpJv0)
## Get Involved with the Community!
Join the [CNCF Slack](https://slack.cncf.io/) and join the `#in-toto-witness` channel. You might also be interested in joining the `#in-toto` channel for more general in-toto discussion, as well as
the `#in-toto-archivista` channel for discussion regarding the [Archivista](https://github.com/in-toto/archivista) project.
## Community & Commercial Support
- **Community channels** – Slack, GitHub Issues, and bi-weekly office hours are free and open to all contributors.
- **Commercial platform & SLAs** – [TestifySec](https://www.testifysec.com) offers managed Witness/Archivista hosting, and 24 × 7 support.
(These commercial services are provided by TestifySec and are not part of the CNCF sponsorship of Witness.)
[demo]: https://raw.githubusercontent.com/in-toto/witness/main/docs/assets/demo.gif "Demo"