conforma / cliLinks
Conforma artifact verifier and policy checker
☆41Updated this week
Alternatives and similar repositories for cli
Users that are interested in cli are comparing it to the libraries listed below
Sorting:
- OPA/Rego policies for use with Conforma☆19Updated this week
- Integration and release of Konflux-CI☆98Updated this week
- ☆254Updated last week
- Superseded by https://github.com/guacsec/trustify☆53Updated last month
- Pipelines-as-Code for Tekton☆172Updated this week
- This repository is an initial set of Argo-CD-based deployments of AppStudio components to a cluster, plus a script to bootstrap Argo CD o…☆54Updated last week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆106Updated this week
- Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supp…☆153Updated this week
- sigstore the hard way!☆118Updated 6 months ago
- ☆25Updated last week
- RapiDAST enables simple, continuous and fully automated application security testing☆83Updated this week
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆71Updated last week
- ☆29Updated this week
- A tool to create, transform and attest VEX metadata☆172Updated last week
- A utility to generate SPDX-compliant Bill of Materials manifests☆437Updated this week
- Supply Chain Security in Tekton Pipelines☆268Updated this week
- Helm Chart for Deploying Backstage. This repo is deprecated. Please move to https://github.com/redhat-developer/rhdh-chart☆63Updated 2 years ago
- kubectl plugin for signing Kubernetes manifest YAML files with sigstore☆85Updated this week
- A CLI tool to sign and verify artifacts☆460Updated 3 weeks ago
- Helm charts for sigstore project☆87Updated this week
- K8s-native AuthN/AuthZ service to protect your APIs.☆240Updated last week
- Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.☆20Updated last week
- A common specification for Continuous Delivery events☆156Updated last week
- ORAS Python SDK☆57Updated 4 months ago
- sigstore installation walkthrough, local☆62Updated last month
- A place for policy work group related proposals and prototypes.☆65Updated 8 months ago
- ☆115Updated last week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆514Updated this week
- CLOMonitor is a tool that periodically checks open source projects repositories to verify they meet certain project health best practices☆144Updated this week
- Hybrid application service creates and manages applications and controls the lifecycle of applications☆22Updated this week