Source-backed facts for citing this resource, derived directly from the registry — also available as plain text for AI assistants.
- Source URLs
- https://docs.github.com/en/actions/how-tos/secure-your-work/use-artifact-attestations/use-artifact-attestations, https://github.com/github/docs
- Brand
- GitHub
- Brand domain
- github.com
- Brand asset source
- brandfetch
- Safety notes
- Artifact attestation verification confirms provenance for a digest, not malware safety, runtime behavior, dependency health, or install trust., Do not approve a release when the verified repository, workflow, ref, subject digest, or commit does not match the artifact being distributed., Keep OIDC and workflow-permission review separate from ordinary release-note editing.
- Privacy notes
- Verification evidence can expose repository names, workflow names, internal release timing, commit SHAs, artifact names, and runner metadata., Public comments should summarize verification without pasting private URLs, unpublished release notes, or internal environment details.
- Platform compatibility
- claude-code (native-skill), codex (native-skill), windsurf (native-skill), gemini (native-skill), cursor (adapter), cli (manual-context)
- Author
- JSONbored
- Submitted by
- JSONbored
- Claim status
- unclaimed
- Last verified
- 2026-06-05