Generating link metadata while carrying out a supply chain step. More information: https://in-toto.readthedocs.io/en/latest/command-line-tools/in-toto-run.html.
in-toto-run -n tag --products . -k key_file -- git tag v1.0
in-toto-run -n package -m project -p project.tar.gz -- tar czf project.tar.gz project
in-toto-run -n review -k key_file -m document.pdf -x
in-toto-run -n scan -k key_file -p report.json -- /bin/sh -c "trivy -o report.json -f json <IMAGE>"