Get started with CI/lock
Capture signed evidence from your existing commands, then inspect and verify the result.
Before you start
Choose a machine or CI runner where you can run a build, test, or scan. You will configure signing as part of the first-attestation guide.
Your first workflow
Check your result
You can inspect the signed attestation for your command and verify it against the policy in the first-attestation guide.
Run it in your workflow
- CI quickstart
Capture evidence from a pipeline.
- GitHub Actions
Add evidence collection to an Actions workflow.
- GitLab CI
Capture and verify evidence in GitLab.
Reference
- CLI commands
Flags, subcommands, and usage.
- Attestors
Choose what CI/lock records.
- Supported tools
Find capture guidance for your existing tools.
Understand the evidence
- Attestations
What the signed record contains.
- Signing and identity
How evidence is attributed.
- Trust models
Choose and understand the verification boundary.
When you need help
- Verify the CI/lock binary
Check the downloaded release.
- Execution support
Check available and planned configurations.
- Frequently asked questions
Answers about capture, signing, and verification.