Publish a signed build provenance from your GitHub Actions workflow
☆62May 21, 2024Updated 2 years ago
Alternatives and similar repositories for generate-build-provenance
Users that are interested in generate-build-provenance are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl…☆11May 11, 2026Updated last month
- Submit SBOMs to GitHub's dependency submission API☆18Dec 4, 2025Updated 6 months ago
- ☆57Jun 1, 2022Updated 4 years ago
- Go implementation of The Update Framework heavily influenced by python-tuf☆14Mar 7, 2024Updated 2 years ago
- A rust implementation of in-toto☆35Jun 3, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Docker CI scripts☆12Nov 24, 2025Updated 6 months ago
- Monorepo for Identity Box☆20Aug 11, 2024Updated last year
- Action for generating build provenance attestations for workflow artifacts☆953Updated this week
- Github Action implementation of SLSA Provenance Generation☆50Updated this week
- An SBOM query language and associated utilities☆56Jan 22, 2024Updated 2 years ago
- GitHub actions for the chainguard-images☆21Updated this week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆34Apr 22, 2025Updated last year
- A java api and command line tool for scanning, reporting and fixing a git repository's InnerSource Readiness based on a supplied specific…☆20Sep 8, 2023Updated 2 years ago
- Run ORT in your GitHub action workflow to do licensing, security and best practices checks and generate reports/SBOMs☆33Jun 2, 2026Updated last week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆114Updated this week
- Tracking manylinux progress on packager side☆26Updated this week
- Enrich SBOMs with data from third party services☆228May 18, 2026Updated 3 weeks ago
- A GitHub Action for sigstore-python☆70Jun 5, 2026Updated last week
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆201Updated this week
- sentry internal pypi☆22Updated this week
- Set timeout-minutes to all GitHub Actions jobs☆36Jun 7, 2026Updated last week
- AWS ECR scanning slack notifications☆13Jul 19, 2023Updated 2 years ago
- A cleaned up Go version of TxtElite☆11Nov 14, 2022Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- playing music using the MRI gradient system☆18Oct 4, 2020Updated 5 years ago
- Owner: DevOps WG☆22Jun 2, 2026Updated last week
- Official GitHub Action for OpenSSF Scorecard.☆384Jun 3, 2026Updated last week
- Help protect against malicious build scripts☆29May 31, 2026Updated 2 weeks ago
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Jul 5, 2023Updated 2 years ago
- Umbrella Repository Service for TUF☆69Jun 3, 2026Updated last week
- ☆22Mar 1, 2026Updated 3 months ago
- AMD Generic Encapsulated Software Architecture Platform Security Processor Configuration Block manipulation library☆18Dec 18, 2025Updated 5 months ago
- A universal SBOM representation in protocol buffers☆326Jun 4, 2026Updated last week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Go library to download OpenTofu with minimal dependencies☆17Oct 27, 2025Updated 7 months ago
- Flancian's digital garden☆27Jun 5, 2026Updated last week
- Contains primitives for marshaling/unmarshaling Unix timestamp/epoch to/from built-in time.Time type in JSON☆17Feb 25, 2024Updated 2 years ago
- A Java implementation of in-toto runlib☆11Jul 23, 2024Updated last year
- A standalone, dependency-free implementation of OpenMetrics v1.0☆10Oct 29, 2025Updated 7 months ago
- A framework for linking the DOM and DOM based events with scripting languages compiled to WASM. Part of the PyScript project.☆12Oct 1, 2024Updated last year
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Jan 27, 2025Updated last year