github-early-access / generate-build-provenance
Publish a signed build provenance from your GitHub Actions workflow
☆63Updated 9 months ago
Alternatives and similar repositories for generate-build-provenance:
Users that are interested in generate-build-provenance are comparing it to the libraries listed below
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆63Updated 4 months ago
- Action for generating attestations for workflow artifacts☆44Updated last week
- A TypeScript library for creating dependency snapshots.☆46Updated last week
- Runner Container Hooks for GitHub Actions☆85Updated 4 months ago
- Go library for Sigstore signing and verification☆58Updated this week
- Official GitHub Action for OpenSSF Scorecard.☆287Updated this week
- Code-signing for npm packages☆161Updated last week
- Purpose-built security agent for hosted runners☆30Updated 7 months ago
- An Action for printing OIDC claims in GitHub Actions.☆83Updated this week
- About GitHub Actions runner images provided by 3rd parties☆106Updated last week
- Runs Dependabot Updates via GitHub Actions.☆95Updated this week
- Find stale repositories in a GitHub organization.☆154Updated last week
- Throw a tag at it and it comes back with a checksum.☆114Updated this week
- GitHub Action to expose GitHub runtime to the workflow☆69Updated 2 weeks ago
- Log monitor for Rekor to verify immutability and monitor entries☆31Updated this week
- ☆20Updated this week
- Find license compliance and security issues in your applications with FOSSA and GitHub Actions.☆51Updated last month
- Verify provenance from SLSA compliant builders☆249Updated 2 weeks ago
- Cosign Github Action☆140Updated 3 weeks ago
- A GitHub App that allows you to contribute upstream using private mirrors of public projects☆161Updated this week
- GitHub Action to combine multiple PRs into a single one☆121Updated 3 weeks ago
- BuildKit Syft scanner☆29Updated last month
- ☆44Updated last week
- Search Rekor for entries☆31Updated last week
- Extract information about the dependencies being updated by a Dependabot-generated PR.☆209Updated last month
- GitHub Action for creating software bill of materials using Syft.☆176Updated 2 weeks ago
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆27Updated 9 months ago
- [Experimental] jail for Go modules☆75Updated this week
- TUF repository for Sigstore trust root☆95Updated this week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆33Updated last month