Owner
RequiredTextSupply a text value for this input.
github
Attestations for a given artifact digest in a repository.
First, connect GitHub in Services. Then open Actions → + → GitHub and choose List Artifact Attestations.
Requires attestations:read on a fine-grained token.
Open an input to choose its value. Keep a fixed value with Text, receive it from Shortcuts, ask when the action runs, or use an Earlier Step. Read how input sources work.
Supply a text value for this input.
github
Supply a text value for this input.
example
SHA256 digest of the artifact, as sha256:HEX.
sha256:b1c2…
provenance, sbom, release, or a custom value.
1–100.
100
In the action editor, open Output → Returned Value to choose fields for your shortcut. These are the response fields described by the app; a service may omit an optional field or return an empty list. JSON File contains the full response.
| Returned field | Type | Meaning |
|---|---|---|
attestations | array | A list of values. |
attestations[].repository_id | integer | Whole-number value. |
attestations[].bundle_url | string | Text value. |
attestations[].bundle | object | A group of named values. |
attestations[].bundle.mediaType | string | Text value. |
If the result is unexpected, open Logs in Shortcutify, select the run, and inspect this step’s inputs and response.
This action supports multiple pages of results. Open its Fetch setting to retrieve more pages when one page is not enough. Each page adds a service request.
Request: GET https://api.github.com/repos/{owner}/{repo}/attestations/{subject_digest}
Action identifier: github.attestations.list.v1
Permissions declared for this action: attestations:read. The account’s own access rules also apply.
| Input | Request key | Location |
|---|---|---|
| Owner | owner | path |
| Repository | repo | path |
| Subject Digest | subject_digest | path |
| Predicate Type | predicate_type | query |
| Page Size | per_page | query |