Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.
☆45Oct 30, 2023Updated 2 years ago
Alternatives and similar repositories for image-layer-provenance
Users that are interested in image-layer-provenance are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆33Updated this week
- Supply Chain Query Tool☆13May 25, 2022Updated 4 years ago
- Example repository that demonstrates a supply chain security workflow using Syft, Grype, Cosign☆12Sep 15, 2021Updated 5 years ago
- Go implementation of witness☆52Updated this week
- Github Action implementation of SLSA Provenance Generation☆50Updated this week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl…☆11Updated this week
- Kubernetes in Docker on Travis-CI☆44Jul 5, 2019Updated 7 years ago
- ☆29Aug 9, 2024Updated 2 years ago
- ☆14Jan 11, 2023Updated 3 years ago
- A trivial wrapper around spf13/cobra to simplify some basic patterns☆21Oct 23, 2023Updated 2 years ago
- Supply Chain Integrity Model☆110Jun 12, 2023Updated 3 years ago
- ☆58Jun 1, 2022Updated 4 years ago
- Action to automatically open a new PR to the https://github.com/withfig/autocomplete repo☆12Sep 4, 2024Updated 2 years ago
- Search Rekor for entries☆51Mar 23, 2026Updated 5 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆151Sep 10, 2026Updated last week
- ☆11Apr 25, 2019Updated 7 years ago
- OCI transport plugin for apt-get (i.e., apt-get over ghcr.io)☆119Jul 20, 2026Updated 2 months ago
- Meeting materials☆26Sep 8, 2026Updated 2 weeks ago
- ☆15Oct 3, 2022Updated 3 years ago
- Sigstore A2A Agent Signing☆27Updated this week
- A specification for signing methods and formats used by Secure Systems Lab projects.☆112Jul 23, 2026Updated 2 months ago
- Comparison of Chainguard Images to others☆21Updated this week
- A docker CLI plugin for verifying signed attestations on images☆13Oct 27, 2023Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- For engineers and security teams driving fast and secure software supply chains☆88Feb 6, 2023Updated 3 years ago
- nginx image demo☆19Sep 11, 2023Updated 3 years ago
- Demos and resources of the Istio + Gatekeeper talks at IstioCon 2022 and GitOpsCon 2022☆16Sep 4, 2023Updated 3 years ago
- A repository to define IETF RATS Concise Reference Integrity Manifest (CoRIM) Data Format Standard for supplying Reference Values and En…☆17Updated this week
- ☆15Jul 24, 2026Updated last month
- BuildKit Syft scanner☆50Updated this week
- Submit SBOMs to GitHub's dependency submission API☆19Dec 4, 2025Updated 9 months ago
- A webhook to use CIVO DNS as a DNS issuer for cert-manager.☆21Mar 8, 2024Updated 2 years ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Nov 1, 2022Updated 3 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Design documents and interoperability tests for Interoperable RA-TLS projects☆15Jul 17, 2026Updated 2 months ago
- Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations☆61Sep 1, 2026Updated 3 weeks ago
- Secure Software Supply Chain Demonstration with Nix☆21May 13, 2025Updated last year
- ☆23Oct 26, 2021Updated 4 years ago
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- Utility for bulk image, license, package, and vulnerability discovery in containerize workloads on GCP. Includes CLI and Service with cus…☆13Feb 15, 2024Updated 2 years ago
- A Java implementation of in-toto runlib☆11Jul 23, 2024Updated 2 years ago