In this guide

List Artifact Attestations

Attestations for a given artifact digest in a repository.

Action referenceRead

What this action does #

First, connect GitHub in Services. Then open Actions → + → GitHub and choose List Artifact Attestations.

More about this action

Requires attestations:read on a fine-grained token.

Inputs to fill in #

Open an input to choose its value. Keep a fixed value with Text, receive it from Shortcuts, ask when the action runs, or use an Earlier Step. Read how input sources work.

Owner

RequiredText

Supply a text value for this input.

Example value (replace with your own):
github

Repository

RequiredText

Supply a text value for this input.

Example value (replace with your own):
example

Subject Digest

RequiredText

SHA256 digest of the artifact, as sha256:HEX.

Example value (replace with your own):
sha256:b1c2…

Predicate Type

OptionalText

provenance, sbom, release, or a custom value.

Page Size

OptionalWhole number

1–100.

Example value (replace with your own):
100

What comes back #

In the action editor, open Output → Returned Value to choose fields for your shortcut. These are the response fields described by the app; a service may omit an optional field or return an empty list. JSON File contains the full response.

Returned fieldTypeMeaning
attestationsarrayA list of values.
attestations[].repository_idintegerWhole-number value.
attestations[].bundle_urlstringText value.
attestations[].bundleobjectA group of named values.
attestations[].bundle.mediaTypestringText value.

Run it from Shortcuts #

  1. Give the action a recognizable name and tap Save.
  2. In Apple Shortcuts, add Shortcutify’s Execute Action and select the saved action.
  3. Supply any Param or File slots you bound in the inputs, then run the shortcut.

If the result is unexpected, open Logs in Shortcutify, select the run, and inspect this step’s inputs and response.

This action supports multiple pages of results. Open its Fetch setting to retrieve more pages when one page is not enough. Each page adds a service request.

Advanced reference #

Request, permissions, and identifiers

Request: GET https://api.github.com/repos/{owner}/{repo}/attestations/{subject_digest}

Action identifier: github.attestations.list.v1

Permissions declared for this action: attestations:read. The account’s own access rules also apply.

InputRequest keyLocation
Ownerownerpath
Repositoryrepopath
Subject Digestsubject_digestpath
Predicate Typepredicate_typequery
Page Sizeper_pagequery

GitHub API reference