chainsaw verify

Verify a package's provenance attestation chain

Verify a package’s provenance attestation chain

chainsaw verify <ecosystem> <package> <version> [flags]

Verify a package’s provenance attestation chain end-to-end. Runs the same checker chainsaw’s intelligence pipeline runs (npm, PyPI, Maven, Go, Docker, APT, …), prints the verified SLSA level, builder identity, source repo + commit, transparency log entry, and exits non-zero on any failure.

This is the primary “show me the chain of custody” tool — operators diagnosing why a policy fired, or auditors confirming a deployment artifact’s claims.

Sigstore verification runs online by default; pass –cache-dir to reuse a previous verification when Rekor/Fulcio are unreachable.

Flags

FlagTypeDefaultDescription
--cache-dirstring—Optional Sigstore bundle cache directory (defaults to no caching)
--cache-ttlduration24h0m0sCache entry TTL when –cache-dir is set
--jsonbool—Emit machine-readable JSON instead of the human chain summary
--source-urlstring—Repository/registry base URL. REQUIRED for apt, yum, dnf and swift; an optional upstream hint elsewhere
--timeoutduration1m0sTotal verification timeout

The global flags apply here too.