docker / buildkit-syft-scannerLinks
BuildKit Syft scanner
☆35Updated last week
Alternatives and similar repositories for buildkit-syft-scanner
Users that are interested in buildkit-syft-scanner are comparing it to the libraries listed below
Sorting:
- Set up your GitHub Actions workflow with a specific version of ORAS☆23Updated this week
- Trivy plugin for OCI referrers☆23Updated last year
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Updated 2 years ago
- Action for generating attestations for workflow artifacts☆59Updated this week
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆43Updated last year
- Various tools, images, etc. to support the Wolfi OSS project☆25Updated this week
- ☆30Updated this week
- Docs and Tutorials for Chainguard☆85Updated this week
- TUF repository for Sigstore trust root☆108Updated last week
- Plugin for Docker CLI to support SBOM creation using Syft☆156Updated 2 weeks ago
- Cosign Github Action☆157Updated this week
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆65Updated last week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆33Updated 4 months ago
- Log monitor for Rekor to verify immutability and monitor entries☆38Updated this week
- A collection of reusable Github Actions workflows.☆141Updated last week
- CLOMonitor is a tool that periodically checks open source projects repositories to verify they meet certain project health best practices☆137Updated last week
- Helm charts for sigstore project☆80Updated this week
- Go library for Sigstore signing and verification☆81Updated last week
- A CLI used to work with the Wolfi OSS project☆67Updated this week
- A sweet little formatter for YAML☆32Updated last week
- Verify provenance from SLSA compliant builders☆284Updated last month
- Dynamic GitHub Actions from Wolfi packages☆44Updated 4 months ago
- ☆67Updated last week
- CLOWarden is a tool that manages access to resources across multiple services☆56Updated last week
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆68Updated this week
- 📈CNCF-created tool for analyzing and graphing developer contributions☆109Updated this week
- Powering the OpenTofu Registry Search (beta)☆18Updated 2 weeks ago
- Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations☆58Updated last week
- 📈DevStats code☆47Updated 3 weeks ago
- GitHub Action for creating software bill of materials using Syft.☆200Updated this week