github-early-access / generate-build-provenance
Publish a signed build provenance from your GitHub Actions workflow
☆63Updated 8 months ago
Alternatives and similar repositories for generate-build-provenance:
Users that are interested in generate-build-provenance are comparing it to the libraries listed below
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆57Updated 3 months ago
- GitHub Action to expose GitHub runtime to the workflow☆64Updated 2 months ago
- Action for generating attestations for workflow artifacts☆43Updated this week
- Official GitHub Action for OpenSSF Scorecard.☆278Updated this week
- An Action for printing OIDC claims in GitHub Actions.☆80Updated 6 months ago
- Runner Container Hooks for GitHub Actions☆81Updated 2 months ago
- A GitHub App that allows you to contribute upstream using private mirrors of public projects☆153Updated this week
- Cosign Github Action☆136Updated last week
- Find stale repositories in a GitHub organization.☆151Updated this week
- Go library for Sigstore signing and verification☆54Updated this week
- Verify provenance from SLSA compliant builders☆243Updated this week
- ☆44Updated this week
- GitHub Action to combine multiple PRs into a single one☆121Updated 3 weeks ago
- GitHub Action to enable automated security updates and open a issue/PR in repos in an org that have dependency files but no dependabot.ya…☆195Updated this week
- ☆20Updated this week
- About GitHub Actions runner images provided by 3rd parties☆97Updated 2 weeks ago
- A TypeScript library for creating dependency snapshots.☆46Updated this week
- A GitHub Action to run the markdownlint-cli2 tool for linting Markdown/CommonMark files with the markdownlint library☆110Updated this week
- BuildKit Syft scanner☆28Updated 3 weeks ago
- Code-signing for npm packages☆161Updated this week
- The containerbase project's base image source☆37Updated this week
- GitHub Action to use Docker Buildx Bake as a high-level build command☆211Updated last week
- GitHub Action to check PRs for signed commits☆50Updated 6 months ago
- Log monitor for Rekor to verify immutability and monitor entries☆30Updated this week
- Throw a tag at it and it comes back with a checksum.☆108Updated last week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆32Updated 3 weeks ago
- GitHub token permissions Monitor and Advisor actions☆267Updated last month
- A tool for testing and debugging Dependabot update jobs.☆265Updated this week
- Find license compliance and security issues in your applications with FOSSA and GitHub Actions.☆50Updated last week
- Purpose-built security agent for hosted runners☆29Updated 6 months ago