A rust implementation of in-toto
☆36Feb 27, 2026Updated last week
Alternatives and similar repositories for in-toto-rs
Users that are interested in in-toto-rs are comparing it to the libraries listed below
Sorting:
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆33Apr 22, 2025Updated 10 months ago
- A Java implementation of in-toto runlib☆11Jul 23, 2024Updated last year
- Keyless Git signing with cosign!☆11May 12, 2022Updated 3 years ago
- Minimal forensic/exfiltration/evil-maid/rescue live boot system☆12Feb 28, 2020Updated 6 years ago
- Helm Chart for deploying GUAC☆18Feb 23, 2026Updated 2 weeks ago
- Experimental script to query rebuilderd for results☆14Dec 4, 2023Updated 2 years ago
- Authenticate a tarball through a signed tag in a git repository (with reproducible builds)☆17May 28, 2022Updated 3 years ago
- TUF Augmentation Proposals (TAPs)☆37Aug 28, 2025Updated 6 months ago
- ☆76Dec 10, 2025Updated 3 months ago
- Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.☆21Mar 2, 2026Updated last week
- Hoppr Cop is a cli and python library that generates high quality vulnerability information from a cyclone-dx Software Bill of Materials …☆25Dec 16, 2024Updated last year
- in-toto Enhancements☆20Feb 17, 2025Updated last year
- A specification for signing methods and formats used by Secure Systems Lab projects.☆94Nov 10, 2025Updated 4 months ago
- Cryptographic and general-purpose routines for Secure Systems Lab projects at NYU☆52Mar 3, 2026Updated last week
- Authenticate the cryptographic chain-of-custody of Linux distributions (like Arch Linux and Debian) to their source code inputs☆28Apr 18, 2025Updated 10 months ago
- Bruteforce with a stream of permutations of a specific pattern☆26Aug 6, 2025Updated 7 months ago
- OpenVEX Specification☆168Jan 16, 2026Updated last month
- Arch Linux Security Update Notifications☆61Jul 28, 2024Updated last year
- Simple Go HTTP client for OCI Distribution, built on top of Resty☆28Jul 18, 2023Updated 2 years ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆108Mar 2, 2026Updated last week
- The "http_guest" crate used by Fastly Labs Terrarium https://wasm.fastlylabs.com/☆29Jan 31, 2019Updated 7 years ago
- A sweet little formatter for YAML☆34Updated this week
- Easy and safe destructuring for more types.☆33Nov 14, 2025Updated 3 months ago
- Run ORT in your GitHub action workflow to do licensing, security and best practices checks and generate reports/SBOMs☆33Feb 24, 2026Updated 2 weeks ago
- Publish a signed build provenance from your GitHub Actions workflow☆63May 21, 2024Updated last year
- oci and apk explorer☆102Dec 17, 2025Updated 2 months ago
- Independent verification of binary packages - Reproducible Builds☆419Jan 8, 2026Updated 2 months ago
- One stop-shop for matplotlib based visualizations☆10Jun 9, 2025Updated 9 months ago
- ☆15Oct 23, 2025Updated 4 months ago
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆145Feb 27, 2026Updated last week
- Determines the MIME type of a file by traversing a filetype tree.☆75Jan 9, 2021Updated 5 years ago
- Find calls to panic functions in rust executables☆36Sep 19, 2021Updated 4 years ago
- Imagine the information security compliance guideline says you need an antivirus but you run Arch Linux☆134Mar 21, 2024Updated last year
- A security layer for Git repositories☆578Mar 3, 2026Updated last week
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Apr 4, 2023Updated 2 years ago
- Model to determine the expected power output of PV-System based on DWD weather forecast data☆13Jan 17, 2024Updated 2 years ago
- Agriculture Land and Commission System☆10Updated this week
- OtterDog is a tool to manage GitHub organizations at scale using a configuration as code approach. It is actively used by the Eclipse Fou…☆46Mar 3, 2026Updated last week
- Collection of Go packages to work with SPDX files☆160Feb 23, 2026Updated 2 weeks ago