glab(1) glab(1)
NAME
glab-attestation-verify - Verify the provenance of a specific artifact
or file. (EXPERIMENTAL)
SYNOPSIS
glab attestation verify [flags]
DESCRIPTION
Verify the provenance of an artifact built by a GitLab CI/CD pipeline.
This command checks the artifact's signed attestation against the
expected GitLab project and pipeline.
This command requires the cosign binary. To install it, see Cosign
installation
.
This command works only on GitLab.com.
For more information about attestations, see:
o Attestations API
o SLSA provenance specification
o SLSA software attestations
This feature is an experiment and is not ready for production use. It
might be unstable or removed at any time. For more information, see
https://docs.gitlab.com/policy/development_stages_support/.
OPTIONS INHERITED FROM PARENT COMMANDS
-h, --help[=false] Show help for this command.
EXAMPLE
# Verify attestation for filename.txt in the gitlab-org/gitlab project
glab attestation verify gitlab-org/gitlab filename.txt
# Verify attestation for filename.txt in the project with ID 123
glab attestation verify 123 filename.txt
SEE ALSO
glab-attestation(1)
Auto generated by spf13/cobra Sep 2026 glab(1)