GH-ATTESTATION-TRUSTED-ROOT(1) GitHub CLI manual (NAME) gh-attestation-trusted-root - (SYNOPSIS) gh attestation trusted-root [--tuf-url --tuf-root ] [--verify-only] [flags] (DESCRIPTION) trusted_root.jsonl . gh attestation verify . --custom-trusted-root trusted_root.jsonl . Sigstore (Sigstore Public Good Instance) Sigstore . --tuf-url (URL) TUF --tuf-root root.json (out-of-band) . TUF trusted_root.jsonl --verify-only . (OPTIONS) --hostname (host) --tuf-root TUF root.json --tuf-url (URL) TUF --verify-only trusted_root.jsonl (EXIT CODES) 0: 1: 2: 4: : . . (EXAMPLES) # trusted_root.jsonl Sigstore Public Good $ gh attestation trusted-root (SEE ALSO) gh-attestation(1) Sep 2026 GH-ATTESTATION-TRUSTED-ROOT(1)