One step in your workflow.
A passport generated once proves one moment. Regenerated on every push, it becomes a ledger: evidence that accumulates for the whole life of the project, in the place your client already trusts.
Add one step
Drop the action into any workflow. It installs the CLI, runs the checks in the runner's own Docker, and generates the passport.
Read the verdict
One summary in the Checks area, outputs for later steps, and honest exit codes: the job fails when checks fail, which is the point.
Seal handovers
At releases, attest the passport with your key or keylessly through Sigstore, or submit it for the signed Mantyl Verified mark without leaving the workflow.
Watch it run for real
The consumer smoke test runs this exact action from the marketplace path against a seeded fixture, in public, with a Sigstore-logged attestation at the end. Check the latest run yourself.
▸ actions › consumer smokeFree. Runs on your runners, in your repo, under your rules. Add .mantyl/ to your .gitignore; passports are artefacts, not commits. The paid step is optional and explicit: one credit, one project, £29.