ietf-scitt / draft-birkholz-scitt-architecture
A specification including, problem statement, use cases, requirements, and architectural constituents for a Transparency Service in support of Supply Chain Integrity, Transparency, and Trust
☆14Updated 2 years ago
Alternatives and similar repositories for draft-birkholz-scitt-architecture:
Users that are interested in draft-birkholz-scitt-architecture are comparing it to the libraries listed below
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆31Updated last year
- An Architecture for Trustworthy Digital Supply Chain Transparency Services☆11Updated this week
- TUF repository for Sigstore trust root☆95Updated this week
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Updated last year
- Visualizer for GUAC☆28Updated last month
- ☆60Updated 7 months ago
- Check SPDX SBOM for NTIA minimum elements☆60Updated last week
- Machine-readable specification for the attestation of security-relevant data.☆57Updated last week
- A TUF repository and signing tool☆28Updated this week
- Example CLI project to demo API architecture and protobom library☆20Updated this week
- ☆19Updated 9 months ago
- Log monitor for Rekor to verify immutability and monitor entries☆30Updated last week
- Specification and other related documents.☆44Updated last month
- SPDX Merge tool☆41Updated this week
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- A specification for signing methods and formats used by Secure Systems Lab projects.☆72Updated 5 months ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆79Updated this week
- A standard API specification for exchanging supply chain artifacts and intelligence☆73Updated last week
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆18Updated this week
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated last month
- in-toto Enhancements☆19Updated 2 weeks ago
- Format agnostic SBOM tooling☆100Updated this week
- ☆100Updated 5 months ago
- Search Rekor for entries☆31Updated this week
- ☆27Updated last week
- The model for the information captured in SPDX version 3 standard.☆77Updated 2 weeks ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Updated 11 months ago
- Umbrella Repository Service for TUF☆45Updated this week
- Technical Advisory Council☆117Updated this week