.nh .TH "glab" "1" "Sep 2026" "Auto generated by spf13/cobra" "" .SH NAME glab-attestation-verify - Verify the provenance of a specific artifact or file. (EXPERIMENTAL) .SH SYNOPSIS \fBglab attestation verify [flags]\fP .SH DESCRIPTION Verify the provenance of an artifact built by a GitLab CI/CD pipeline. This command checks the artifact's signed attestation against the expected GitLab project and pipeline. .PP This command requires the cosign binary. To install it, see Cosign installation \[la]https://docs.sigstore.dev/cosign/system_config/installation/\[ra]\&. .PP This command works only on GitLab.com. .PP For more information about attestations, see: .IP \(bu 2 Attestations API \[la]https://docs.gitlab.com/api/attestations/\[ra] .IP \(bu 2 SLSA provenance specification \[la]https://docs.gitlab.com/ci/pipeline_security/slsa/provenance_v1/\[ra] .IP \(bu 2 SLSA software attestations \[la]https://slsa.dev/spec/v1.2/attestation\-model\[ra] .PP This feature is an experiment and is not ready for production use. It might be unstable or removed at any time. For more information, see https://docs.gitlab.com/policy/development_stages_support/. .SH OPTIONS INHERITED FROM PARENT COMMANDS \fB-h\fP, \fB--help\fP[=false] Show help for this command. .SH EXAMPLE .EX # Verify attestation for filename.txt in the gitlab-org/gitlab project glab attestation verify gitlab-org/gitlab filename.txt # Verify attestation for filename.txt in the project with ID 123 glab attestation verify 123 filename.txt .EE .SH SEE ALSO \fBglab-attestation(1)\fP