Security Testing
in-toto: Software Supply Chain Attestations and Verification
in-toto is the foundational framework for software supply chain security that powers much of modern tooling — including SLSA provenance and Sigstore attestations. Understanding in-toto means understanding the underlying model that these higher-level tools implement. The Problem in-toto Solves The SolarWinds attack succeeded because attackers compromised the