actions / attest
Action for generating attestations for workflow artifacts
☆33Updated this week
Related projects ⓘ
Alternatives and complementary repositories for attest
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆36Updated last week
- BuildKit Syft scanner☆26Updated 2 months ago
- About GitHub Actions runner images provided by 3rd parties☆64Updated 4 months ago
- Protocol Buffer specifications☆23Updated this week
- Action for generating SBOM attestations for workflow artifacts☆19Updated this week
- Publish a signed build provenance from your GitHub Actions workflow☆63Updated 6 months ago
- An Action for printing OIDC claims in GitHub Actions.☆76Updated 3 months ago
- Find license compliance and security issues in your applications with FOSSA and GitHub Actions.☆46Updated last month
- The containerbase project's base image source☆35Updated this week
- GitHub Action to check PRs for signed commits☆45Updated 3 months ago
- Cosign Github Action☆126Updated 3 weeks ago
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆95Updated 7 months ago
- ☆15Updated 5 months ago
- A TypeScript library for creating dependency snapshots.☆46Updated last month
- Calculates dependencies for a Go build-target and submits the list to the Dependency Submission API☆52Updated 4 months ago
- A High-Availability distribution of Knative.☆20Updated 8 months ago
- Sigstore user stories☆29Updated last year
- Repo for building the renovate/renovate:full image☆40Updated 9 months ago
- ☆42Updated 2 months ago
- Log monitor for Rekor to verify immutability and monitor entries☆26Updated this week
- ☆24Updated last year
- Go library for Sigstore signing and verification☆48Updated this week
- Set up your GitHub Actions workflow with a specific version of ORAS☆15Updated this week
- Go module implementing general types to represent any way of referencing images within distribution☆32Updated 4 months ago
- Golang implementation of a checker for determining if an SPDX ID satisfies an SPDX Expression.☆31Updated this week
- Powering the OpenTofu Registry Search (beta)☆12Updated this week
- ☆15Updated 8 months ago
- Dockerfile examples for reproducing package cache (e.g., `/etc/apk/cache`)☆12Updated last year
- ☆30Updated 3 weeks ago
- Purpose-built security agent for hosted runners☆29Updated 3 months ago