Your CI builds machine images. But can you prove one wasn't tampered with?
Packer v1.16.0 ships native SLSA provenance: generate, sign, and verify cryptographic attestations for every image you build. No extra tooling.
Supply-chain security just got built in. Read more: