# Generate SLSA build provenance in GitHub Actions

> Attach signed SLSA provenance to GitHub Actions builds so release artifacts ship with verifiable supply-chain metadata.

- Skill: `agentskillexchange/generate-slsa-build-provenance-in-github-actions` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/generate-slsa-build-provenance-in-github-actions`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/generate-slsa-build-provenance-in-github-actions/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/generate-slsa-build-provenance-in-github-actions

---


# Generate SLSA build provenance in GitHub Actions

Attach signed SLSA provenance to GitHub Actions builds so release artifacts ship with verifiable supply-chain metadata.

## Prerequisites

GitHub Actions, SLSA GitHub Generator

## Installation

Requirements and caveats from upstream:
- [![docker-bench-security stars](https://img.shields.io/github/stars/docker/docker-bench-security?logo=github&label=docker/docker-bench-security)](https://github.com/docker/docker-bench-security)
- [![powertools-lambda-python stars](https://img.shields.io/github/stars/aws-powertools/powertools-lambda-python?logo=github&label=aws-powertools/powertools-lambda-python)](https://github.com/aws-powertools/powertools-l...
- | [Node.js](https://nodejs.org) projects | [Node.js Builder](internal/builders/nodejs/README.md) | Builds and generates provenance for npm packages | [Beta since v1.6.0](https://github.com/slsa-framework/slsa-github-g...

Basic usage or getting-started notes:
- [SLSA Build level 3 and above](https://slsa.dev/spec/v1.0/levels). See some
- [popular projects](#hall-of-fame) generating provenance using this project.
- tools for building a SLSA builder on GitHub using the

- Source: https://github.com/slsa-framework/slsa-github-generator
- Extracted from upstream docs: https://raw.githubusercontent.com/slsa-framework/slsa-github-generator/HEAD/README.md

## Documentation

- https://github.com/slsa-framework/slsa-github-generator

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/generate-slsa-build-provenance-in-github-actions/)

