Skip to content

List attestations

GET
/users/{username}/attestations/{subject_digest}

List a collection of artifact attestations with a given subject digest that are associated with repositories owned by a user.

The collection of attestations returned by this endpoint is filtered according to the authenticated user’s permissions; if the authenticated user cannot read a repository, the attestations associated with that repository will not be included in the response. In addition, when using a fine-grained access token the attestations:read permission is required.

Please note: in order to offer meaningful security benefits, an attestation’s signature and timestamps must be cryptographically verified, and the identity of the attestation signer must be validated. Attestations can be verified using the GitHub CLI attestation verify command. For more information, see our guide on how to use artifact attestations to establish a build’s provenance.

API method documentation

username
required
string

The handle for the GitHub user account.

subject_digest
required
string

Subject Digest

per_page
integer
default: 30

The number of results per page (max 100). For more information, see “Using pagination in the REST API.”

before
string

A cursor, as given in the Link header. If specified, the query only searches for results before this cursor. For more information, see “Using pagination in the REST API.”

after
string

A cursor, as given in the Link header. If specified, the query only searches for results after this cursor. For more information, see “Using pagination in the REST API.”

predicate_type
string

Optional filter for fetching attestations with a given predicate type. This option accepts provenance, sbom, release, or freeform text for custom predicate types.

Response

Media typeapplication/json
object
attestations
Array<object>
object
bundle

The attestation’s Sigstore Bundle. Refer to the Sigstore Bundle Specification for more information.

object
mediaType
string
verificationMaterial
object
key
additional properties
any
dsseEnvelope
object
key
additional properties
any
repository_id
integer
bundle_url
string
initiator
string
Examples
Exampledefault
{
"attestations": [
{
"repository_id": 1,
"bundle_url": "https://tmastaging.blob.core.windows.net/attestations/1/2024/11/08/4.json.sn?se=2024-11-09T17%3A13%3A43Z&sig=jPSbbJnIEshUyCjBLU5Ykq0uuGc5UYxTZE1%2FhdBNMXk%3D&sp=r&spr=https%2Chttp&sr=b&st=2024-11-08T17%3A13%3A43Z&sv=2024-08-04",
"initiator": "user"
},
{
"repository_id": 1,
"bundle_url": "https://tmastaging.blob.core.windows.net/attestations/1/2024/11/08/5.json.sn?se=2024-11-09T17%3A13%3A43Z&sig=jPSbbJnIEshUyCjBLU5Ykq0uuGc5UYxTZE1%2FhdBNMXk%3D&sp=r&spr=https%2Chttp&sr=b&st=2024-11-08T17%3A13%3A43Z&sv=2024-08-04",
"initiator": "user"
}
]
}

Response

Media typeapplication/json
Empty Object

An object without any properties.

object
Examples
Exampledefault
null

Response

Resource not found

Media typeapplication/json
Basic Error

Basic Error

object
message
string
documentation_url
string
url
string
status
string
Examplegenerated
{
"message": "example",
"documentation_url": "example",
"url": "example",
"status": "example"
}