goreleaser / example-supply-chainLinks
Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations
β58Updated last week
Alternatives and similar repositories for example-supply-chain
Users that are interested in example-supply-chain are comparing it to the libraries listed below
Sorting:
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.β63Updated this week
- π Rekor transparency log monitoring and alertingβ27Updated last year
- native go library for installation and management of apk packagesβ29Updated last year
- β20Updated last month
- Build and deploy Go applications with Terraformβ29Updated this week
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.β43Updated last year
- Sigstore user storiesβ30Updated last year
- Transparenty Immutable Container Image Tagsβ20Updated 2 years ago
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.β66Updated last week
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.β139Updated 2 weeks ago
- A CLI used to work with the Wolfi OSS projectβ63Updated this week
- Tool to automate build instructions generationβ33Updated this week
- To manage Docker Content Trust and Notary certificatesβ13Updated last week
- Integrates Spiffe and Vault to have secretless authenticationβ90Updated last week
- β29Updated 11 months ago
- β57Updated 3 years ago
- β23Updated 2 years ago
- oci and apk explorerβ58Updated 2 weeks ago
- Trust Dexter to ensure that all your images are pinned by digest for better securityβ29Updated last year
- Example project using SLSA 3 Generic Generator with GoReleaserβ10Updated last year
- Terraform provider for Sigstore Cosignβ11Updated last week
- A collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications.β41Updated last week
- Go module to generate and transform VEX documentsβ43Updated 3 weeks ago
- OpenCP shim is a simple HTTP server that implements the Kubernetes API server interface. It is a shim that allows you to use the Kubernetβ¦β14Updated 2 years ago
- Dynamic GitHub Actions from Wolfi packagesβ43Updated last month
- A collection of Dagger modules powered by Dagger.β15Updated 7 months ago
- Helm charts for sigstore projectβ77Updated this week
- Helper methods for Magefilesβ33Updated 2 years ago
- A basic website that shows the timeline of Kubernetes Core APIsβ26Updated 3 months ago
- β20Updated last month