fepitre / debrebuild
Given a buildinfo file from a Debian package, generate instructions for attempting to reproduce the binary packages built from the associated source and build information.
☆17Updated 2 years ago
Alternatives and similar repositories for debrebuild:
Users that are interested in debrebuild are comparing it to the libraries listed below
- Supply Chain Query Tool☆13Updated 2 years ago
- DSL language to write seccomp filters☆36Updated 9 months ago
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆41Updated last year
- An http proxy for reproducibility.☆19Updated 2 years ago
- Run any command transparently in a VM (this repo isn't part of Cappsule)☆27Updated 7 years ago
- Linux kernel - See Landlock issues☆35Updated last month
- A specification for signing methods and formats used by Secure Systems Lab projects.☆70Updated 4 months ago
- Extended verification for git tags☆133Updated 2 years ago
- sget is a keyless safe script retrieval and execution tool☆18Updated 2 years ago
- Service to scan licenses from source code☆12Updated last year
- The Unreproducible Package☆61Updated last month
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- egrets monitors egress☆46Updated 4 years ago
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆31Updated last year
- Sandboxing File System☆46Updated 5 years ago
- Rewritten Clevis TPM2 PIN☆16Updated 8 months ago
- K8S Operator for Rekor☆20Updated last year
- Build custom Docker seccomp profiles for containers by finding syscalls it uses.☆89Updated 4 years ago
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Updated last year
- A simple, self-contained regression test suite for the Linux Kernel's audit subsystem☆22Updated 4 months ago
- Enabling continuous integration for patch-based development workflows.☆79Updated 9 months ago
- Specification and other related documents.☆43Updated 2 weeks ago
- A tool to list and diagnose bpf programs. (Who watches the watchers..? :)☆95Updated 4 years ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆18Updated this week
- Automating Compliance Tooling Project☆20Updated 3 years ago
- IPE is a Linux Security Module (LSM), which allows for a configurable policy to enforce integrity requirements on the whole system. IPE b…☆60Updated this week
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆32Updated last year
- Stores Chromium Channel ID private keys in an Intel SGX enclave.☆33Updated 8 years ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- A monitor that checks that Certificate Transparency Logs are complying with RFC 6962 and the Chromium Certificate Transparency Log Policy…☆40Updated last year