Supply Chain Integrity Model
☆106Jun 12, 2023Updated 2 years ago
Alternatives and similar repositories for scim
Users that are interested in scim are comparing it to the libraries listed below
Sorting:
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl…☆11Jan 26, 2026Updated last month
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆145Feb 13, 2026Updated 2 weeks ago
- Supply Chain Query Tool☆13May 25, 2022Updated 3 years ago
- Production grade Kubernetes controller for managing AWS Services using CRDs☆16Apr 8, 2020Updated 5 years ago
- Demos and resources of the Istio + Gatekeeper talks at IstioCon 2022 and GitOpsCon 2022☆14Sep 4, 2023Updated 2 years ago
- Scans SBOMs for vulnerabilities with Grype☆85Feb 21, 2026Updated last week
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆45Oct 30, 2023Updated 2 years ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Jan 27, 2025Updated last year
- General sigstore community repo☆44Updated this week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆33Apr 22, 2025Updated 10 months ago
- This repo is a consolidation of Secure Software Supply Chain resources, such as talks, whitepapers, conferences and more.☆139Jul 12, 2022Updated 3 years ago
- A community collection of security reviews of open source software components.☆97Feb 29, 2024Updated 2 years ago
- A GitHub Action for using Conftest☆33Nov 29, 2021Updated 4 years ago
- CDK app to setup an isolated AWS network to experiment with ways of exfiltrating data☆18Nov 18, 2021Updated 4 years ago
- ☆22Nov 27, 2021Updated 4 years ago
- A CVRF CSAF Converter, taking care about OASIS specification.☆10Jun 4, 2025Updated 8 months ago
- 🥑 Inspect and understand an organization's software supply chain using AI to enable stakeholders to make actionable decisions about soft…☆22Apr 15, 2024Updated last year
- ☆23Mar 13, 2023Updated 2 years ago
- Simple implementation of an AppSec Pipeline using the Gasp library☆13Sep 8, 2019Updated 6 years ago
- A Java implementation of in-toto runlib☆11Jul 23, 2024Updated last year
- Kyverno extension service for Notation and the AWS signer☆15Updated this week
- ☆102Sep 27, 2024Updated last year
- ☆76Dec 10, 2025Updated 2 months ago
- A Go program to display certificate chains simply and quickly with an easy to remember syntax☆28Oct 28, 2024Updated last year
- OASIS CSAF TC: Supporting version control for Work Product artifacts developed by members of TC, including prose specifications and secon…☆210Updated this week
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆24Feb 19, 2026Updated last week
- apt2sbom python package generates SPDX or CycloneDX files from Ubuntu APT and Python packaging information☆25Feb 4, 2022Updated 4 years ago
- Keyless Git signing with cosign!☆11May 12, 2022Updated 3 years ago
- Apfell POC Chrome Extension Payload☆10Jun 24, 2020Updated 5 years ago
- A utility library for go☆13Oct 26, 2017Updated 8 years ago
- A template repository for building external data providers for Gatekeeper.☆12Aug 14, 2023Updated 2 years ago
- demo of keyless signing with the sigstore kubernetes policy controller☆11Sep 7, 2022Updated 3 years ago
- An example repo demonstrating keyless signing with Github Actions☆11May 24, 2022Updated 3 years ago
- Red team tool that emulates the SolarWinds CI compromise attack vector.☆24Mar 15, 2024Updated last year
- Community Specification 1.0☆73Updated this week
- verify https assets with a public transparency log☆75Oct 28, 2021Updated 4 years ago
- vexctl is a tool to attest VEX impact statements☆45Mar 27, 2023Updated 2 years ago
- Open Source Software Secure Supply Chain Framework☆239Oct 28, 2022Updated 3 years ago
- Rust implementation of OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆28Jul 29, 2025Updated 6 months ago