Provenance
3 tutorials in this category.
01
How to Verify Package Provenance with SLSA Attestations
Understand provenance statuses, create policies that require verified provenance, and interpret provenance data in the BOM.
02
How to Detect Mirror Tampering with APT, Yum, and DNF Hash-Chain Provenance
Enable end-to-end clearsigned InRelease + repomd.xml.asc verification for OS package mirrors by configuring the trust-root keyring.
04
How to Verify MCP-Server Provenance for Claude / GPT Agent Dependencies
An MCP server is a tool you give an LLM. Treat it like one. This guide shows how Chainsaw flags npm and pip packages that ship MCP server descriptors, scores their provenance, and gates which servers can reach your agent runtimes.