fepitre / debrebuild
Given a buildinfo file from a Debian package, generate instructions for attempting to reproduce the binary packages built from the associated source and build information.
☆17Updated 2 years ago
Alternatives and similar repositories for debrebuild:
Users that are interested in debrebuild are comparing it to the libraries listed below
- Supply Chain Query Tool☆13Updated 2 years ago
- A Java implementation of in-toto runlib☆11Updated 7 months ago
- Service to scan licenses from source code☆12Updated last year
- An http proxy for reproducibility.☆19Updated 2 years ago
- DSL language to write seccomp filters☆36Updated 10 months ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆41Updated last year
- Linux kernel - See Landlock issues☆36Updated 2 months ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆18Updated this week
- A TUF repository and signing tool☆28Updated this week
- K8S Operator for Rekor☆20Updated 2 years ago
- A specification for signing methods and formats used by Secure Systems Lab projects.☆72Updated 5 months ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated last month
- egrets monitors egress☆46Updated 4 years ago
- sget is a keyless safe script retrieval and execution tool☆18Updated 3 years ago
- mozilla: Firefox's X.509 certificate verification core code.☆22Updated 9 years ago
- Securing open-source package ecosystems by originating, validating, and augmenting build attestations.☆33Updated this week
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Updated last year
- The Great Multi-Factor Authentication (MFA) Distribution Project of the Open Source Security Foundation (OpenSSF). We work to distribute …☆54Updated 3 years ago
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆31Updated last year
- TUF Augmentation Proposals (TAPs)☆32Updated 10 months ago
- Run any command transparently in a VM (this repo isn't part of Cappsule)☆27Updated 7 years ago
- IPE is a Linux Security Module (LSM), which allows for a configurable policy to enforce integrity requirements on the whole system. IPE b…☆60Updated last month
- A high level language for SELinux policy☆57Updated this week
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.☆14Updated last week
- The Unreproducible Package☆62Updated last week
- Static code analysis of refpolicy style SELinux policy☆42Updated last month
- Cryptographic and general-purpose routines for Secure Systems Lab projects at NYU☆49Updated last week
- Enterprise Linux Exploit Mapper☆28Updated 7 years ago