Skip to content

List attestations

GET
/repos/{owner}/{repo}/attestations/{subject_digest}

List a collection of artifact attestations with a given subject digest that are associated with a repository.

The authenticated user making the request must have read access to the repository. In addition, when using a fine-grained access token the attestations:read permission is required.

Please note: in order to offer meaningful security benefits, an attestation’s signature and timestamps must be cryptographically verified, and the identity of the attestation signer must be validated. Attestations can be verified using the GitHub CLI attestation verify command. For more information, see our guide on how to use artifact attestations to establish a build’s provenance.

API method documentation

owner
required
string

The account owner of the repository. The name is not case sensitive.

repo
required
string

The name of the repository without the .git extension. The name is not case sensitive.

subject_digest
required
string

The parameter should be set to the attestation’s subject’s SHA256 digest, in the form sha256:HEX_DIGEST.

per_page
integer
default: 30

The number of results per page (max 100). For more information, see “Using pagination in the REST API.”

before
string

A cursor, as given in the Link header. If specified, the query only searches for results before this cursor. For more information, see “Using pagination in the REST API.”

after
string

A cursor, as given in the Link header. If specified, the query only searches for results after this cursor. For more information, see “Using pagination in the REST API.”

predicate_type
string

Optional filter for fetching attestations with a given predicate type. This option accepts provenance, sbom, release, or freeform text for custom predicate types.

Response

Media typeapplication/json
object
attestations
Array<object>
object
bundle

The attestation’s Sigstore Bundle. Refer to the Sigstore Bundle Specification for more information.

object
mediaType
string
verificationMaterial
object
key
additional properties
any
dsseEnvelope
object
key
additional properties
any
repository_id
integer
bundle_url
string
initiator
string
Examples
Exampledefault
{
"attestations": [
{
"repository_id": 1,
"bundle_url": "https://tmastaging.blob.core.windows.net/attestations/1/2024/11/08/4.json.sn?se=2024-11-09T17%3A13%3A43Z&sig=jPSbbJnIEshUyCjBLU5Ykq0uuGc5UYxTZE1%2FhdBNMXk%3D&sp=r&spr=https%2Chttp&sr=b&st=2024-11-08T17%3A13%3A43Z&sv=2024-08-04",
"initiator": "user"
},
{
"repository_id": 1,
"bundle_url": "https://tmastaging.blob.core.windows.net/attestations/1/2024/11/08/5.json.sn?se=2024-11-09T17%3A13%3A43Z&sig=jPSbbJnIEshUyCjBLU5Ykq0uuGc5UYxTZE1%2FhdBNMXk%3D&sp=r&spr=https%2Chttp&sr=b&st=2024-11-08T17%3A13%3A43Z&sv=2024-08-04",
"initiator": "user"
}
]
}