artifact attestation
A signed statement, created in a workflow, that ties an artifact's digest to the repository, workflow and commit that built it.
The attest action signs it through Sigstore using the job's OIDC token, which gives SLSA build level 2. Consumers check it with gh attestation verify before trusting the artifact.