chainsaw verify
Verify a package's provenance attestation chain
Verify a package’s provenance attestation chain
chainsaw verify <ecosystem> <package> <version> [flags]
Verify a package’s provenance attestation chain end-to-end. Runs the same checker chainsaw’s intelligence pipeline runs (npm, PyPI, Maven, Go, Docker, APT, …), prints the verified SLSA level, builder identity, source repo + commit, transparency log entry, and exits non-zero on any failure.
This is the primary “show me the chain of custody” tool — operators diagnosing why a policy fired, or auditors confirming a deployment artifact’s claims.
Sigstore verification runs online by default; pass –cache-dir to reuse a previous verification when Rekor/Fulcio are unreachable.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--cache-dir | string | — | Optional Sigstore bundle cache directory (defaults to no caching) |
--cache-ttl | duration | 24h0m0s | Cache entry TTL when –cache-dir is set |
--json | bool | — | Emit machine-readable JSON instead of the human chain summary |
--source-url | string | — | Repository/registry base URL. REQUIRED for apt, yum, dnf and swift; an optional upstream hint elsewhere |
--timeout | duration | 1m0s | Total verification timeout |
The global flags apply here too.