in-toto

A framework to secure the integrity of software supply chains

Specifications

Stable (v0.9) This is a thoroughly-reviewed version of the specification (and probably what you're looking for)
Latest If you want to see what are the latest changes and possible features, click this.