qa-slsa
Supply chain provenance verification using SLSA attestations. Verifies that build artifacts (npm packages, Docker images, release binaries) have valid SLSA provenance attestations chaining to a trusted CI environment. Flags unsigned or tampered artifacts as CI failures. Integrates with gh CLI attestation and slsa-verifier. Env vars: SLSA_MIN_LEVEL. (qa-agentic-team)