attestation inspects artifact provenance.
Build provenance is part of supply-chain security and release confidence.
Use attestation when validating release artifacts, deployment inputs, or
repository compliance.
Use a profile that can read the repository and its artifact provenance metadata. Attestation availability depends on the provider and on whether the repository publishes provenance for the artifacts you care about.
gitfleet attestation list --repo owner/repository
GitHub supports attestation operations. GitLab currently reports this capability as unsupported.
These commands are read-only.
Use --json for release gates and compliance checks.