Security & supply chainPacker 1.16 ships signed SLSA provenance, and a command to check it
Packer v1.16.0 emits signed SLSA Provenance v1 attestations for every machine image it builds, and adds a verify-attestation command so downstream pipelines can actually check the signature before promoting an AMI or a VM template.