glab(1) glab(1)

glab-attestation-verify - Verify the provenance of a specific artifact or file. (EXPERIMENTAL)

glab attestation verify [flags]

Verify the provenance of an artifact built by a GitLab CI/CD pipeline. This command checks the artifact's signed attestation against the expected GitLab project and pipeline.

This command requires the cosign binary. To install it, see Cosign installation ⟨https://docs.sigstore.dev/cosign/system_config/installation/⟩.

This command works only on GitLab.com.

For more information about attestations, see:

This feature is an experiment and is not ready for production use. It might be unstable or removed at any time. For more information, see https://docs.gitlab.com/policy/development_stages_support/.

-h, --help[=false] Show help for this command.

# Verify attestation for filename.txt in the gitlab-org/gitlab project
glab attestation verify gitlab-org/gitlab filename.txt
# Verify attestation for filename.txt in the project with ID 123
glab attestation verify 123 filename.txt

glab-attestation(1)

Jun 2026 Auto generated by spf13/cobra