Publish a signed build provenance from your GitHub Actions workflow
☆62May 21, 2024Updated 2 years ago
Alternatives and similar repositories for generate-build-provenance
Users that are interested in generate-build-provenance are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl…☆11May 11, 2026Updated 2 weeks ago
- Submit SBOMs to GitHub's dependency submission API☆18Dec 4, 2025Updated 5 months ago
- Go implementation of The Update Framework heavily influenced by python-tuf☆14Mar 7, 2024Updated 2 years ago
- Generates SPDX bill-of-material files from a package input and license scan☆13Apr 15, 2024Updated 2 years ago
- Supply Chain Query Tool☆13May 25, 2022Updated 3 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A rust implementation of in-toto☆35Feb 27, 2026Updated 2 months ago
- Monorepo for Identity Box☆20Aug 11, 2024Updated last year
- Action for generating build provenance attestations for workflow artifacts☆940Mar 4, 2026Updated 2 months ago
- Github Action implementation of SLSA Provenance Generation☆50Updated this week
- An SBOM query language and associated utilities☆56Jan 22, 2024Updated 2 years ago
- A java api and command line tool for scanning, reporting and fixing a git repository's InnerSource Readiness based on a supplied specific…☆20Sep 8, 2023Updated 2 years ago
- Run ORT in your GitHub action workflow to do licensing, security and best practices checks and generate reports/SBOMs☆33May 5, 2026Updated 2 weeks ago
- Language-agnostic SLSA provenance generation for Github Actions☆573Mar 29, 2026Updated last month
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆111May 16, 2026Updated last week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆23Oct 26, 2021Updated 4 years ago
- Tracking manylinux progress on packager side☆25Updated this week
- A GitHub Action for sigstore-python☆68Updated this week
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆19Updated this week
- Libs and tools used to build all *-version tools for GitHub Actions☆31May 11, 2026Updated last week
- Set timeout-minutes to all GitHub Actions jobs☆36Updated this week
- Dependency lockfiles for reproducible build environments 📦🔒☆50May 18, 2026Updated last week
- playing music using the MRI gradient system☆15Oct 4, 2020Updated 5 years ago
- Owner: DevOps WG☆22Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Official GitHub Action for OpenSSF Scorecard.☆379May 13, 2026Updated last week
- Umbrella Repository Service for TUF☆68May 14, 2026Updated last week
- Basic integration of truffle and React front-end based on the create-react-app without resorting to the 'reject' mode.☆13Sep 6, 2018Updated 7 years ago
- ☆22Mar 1, 2026Updated 2 months ago
- AMD Generic Encapsulated Software Architecture Platform Security Processor Configuration Block manipulation library☆17Dec 18, 2025Updated 5 months ago
- A universal SBOM representation in protocol buffers☆324May 17, 2026Updated last week
- Go library to download OpenTofu with minimal dependencies☆17Oct 27, 2025Updated 6 months ago
- MVP for updated PEP 543 proposal☆14Apr 17, 2026Updated last month
- Flancian's digital garden☆27Updated this week
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A Java implementation of in-toto runlib☆11Jul 23, 2024Updated last year
- Real-time node group observability for AWS EKS☆24Apr 21, 2025Updated last year
- A framework for linking the DOM and DOM based events with scripting languages compiled to WASM. Part of the PyScript project.☆12Oct 1, 2024Updated last year
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Jan 27, 2025Updated last year
- Example repo showing how to build wheels with cibuildwheel and automatically upload to PyPI on every tag☆15Nov 1, 2021Updated 4 years ago
- A tool for generating OIDC identities☆15May 1, 2026Updated 3 weeks ago
- Rez CLI/GUI tool for installing packages from developer package repositories.☆12Nov 25, 2021Updated 4 years ago