sk Skill · harness
enforce-slsa
Add an SLSA Verification (SlsaVerification) step to an existing Harness pipeline to verify SLSA provenance attestations and optionally enforce OPA policy sets on provenance data. Supports CI and CD (Deployment) including CI-only pipelines — append a Deploy stage via Phase 3b when verifying before deploy. Supports Docker, ECR, GCR, GAR, ACR, HAR, and Local artifacts. Only works with existing pipelines. Use when asked…
Open on skills.sh ↗read 2026-09-15
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
yamlShell
- Host repository
- harness/harness-skills
- Version
- 1.0.0
- Compatible with
- Requires Harness MCP v2 server (harness-mcp-v2)
- Licence
- Apache-2.0
- Host stars
- 106
- Host language
- Shell