carabiner-dev / ampelLinks
π΄π‘π’ The Amazing Multipurpose Policy Engine (and L)
β12Updated this week
Alternatives and similar repositories for ampel
Users that are interested in ampel are comparing it to the libraries listed below
Sorting:
- A tool to create, transform and attest VEX metadataβ151Updated last week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for soβ¦β98Updated this week
- sigstore the hard way!β115Updated 2 weeks ago
- β243Updated this week
- β63Updated last year
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.β68Updated last week
- β23Updated 3 years ago
- Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable suppβ¦β141Updated last week
- Go implementation of witnessβ36Updated last week
- An http proxy for reproducibility.β19Updated 2 years ago
- β14Updated 4 months ago
- sigstore installation walkthrough, localβ62Updated last year
- Format agnostic SBOM toolingβ114Updated this week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utilityβ60Updated 2 years ago
- Scans SBOMs for vulnerabilities with Grypeβ84Updated this week
- in-toto Attestation Frameworkβ291Updated 2 weeks ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI toolsβ18Updated last week
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.β140Updated last week
- Generate a score for your sbom to understand if it will actually be useful.β232Updated last year
- A CLI tool for creating secure by design/default source repos.β26Updated last year
- β57Updated 3 years ago
- Helm charts for sigstore projectβ78Updated this week
- β11Updated 2 years ago
- kubectl plugin for signing Kubernetes manifest YAML files with sigstoreβ84Updated last month
- Go library for Sigstore signing and verificationβ79Updated last week
- vexctl is a tool to attest VEX impact statementsβ45Updated 2 years ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact proβ¦β492Updated this week
- A utility to generate SPDX-compliant Bill of Materials manifestsβ403Updated last week
- Search an SBOM for licenses and the packages they belong toβ100Updated this week
- Go module to generate and transform VEX documentsβ46Updated this week