10 results found Sort:
- Filter by Primary Language:
- Go (7)
- Python (1)
- +
Language-agnostic SLSA provenance generation for Github Actions
Created
2022-03-28
1,042 commits to main branch, last one 4 days ago
Chainloop is an Open Source evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, CSAF files, QA reports, and more.
Created
2023-03-06
1,141 commits to main branch, last one a day ago
Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks, detec...
Created
2022-12-05
500 commits to main branch, last one 25 days ago
A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the ...
Created
2023-07-28
88 commits to main branch, last one 10 months ago
Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance
Created
2023-01-12
330 commits to main branch, last one 10 months ago
Developer-centric tool to secure your software supply chain.
Created
2024-05-31
301 commits to main branch, last one 4 days ago
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Created
2022-07-09
840 commits to main branch, last one a day ago
Github Action implementation of SLSA Provenance Generation
Created
2021-09-13
535 commits to main branch, last one 12 days ago
Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.
This repository has been archived
(exclude archived)
Created
2022-08-05
24 commits to main branch, last one 2 years ago
GitHub Action to generate an attestation for the build provenance of a plugin ZIP file on WordPress.org
Created
2024-11-15
59 commits to trunk branch, last one 23 hours ago