omnibor / spec
A draft standard for communicating a cryptographic record of build inputs for software artifacts.
☆23Updated last month
Related projects ⓘ
Alternatives and complementary repositories for spec
- bomsh is collection of tools to explore the OmniBOR idea☆21Updated 3 weeks ago
- A specification for signing methods and formats used by Secure Systems Lab projects.☆68Updated 2 months ago
- ☆24Updated last year
- Protocol Buffer specifications☆23Updated this week
- An SBOM query language and associated utilities☆54Updated 10 months ago
- A tool that takes two or more micro SBOMs and composes them into one distributable SBOM☆23Updated last year
- Various tools, images, etc. to support the Wolfi OSS project☆19Updated this week
- Lint your Rego policies inside of Visual Studio Code☆15Updated 5 months ago
- This tool allows using a SPIFFE JWT to authenticate to AWS APIs☆35Updated 5 months ago
- ☆38Updated this week
- A Kubernetes admission controller driven by open-feature☆13Updated last year
- Go reference implementation of Swerve☆11Updated 3 months ago
- A minimal private module registry for Terraform and OpenTofu☆30Updated this week
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆41Updated last year
- ☆30Updated 3 weeks ago
- Firecracker IN Docker - MicroVM inside containers☆32Updated 3 years ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 2 weeks ago
- ☆26Updated this week
- Helm Chart for deploying GUAC☆14Updated 3 months ago
- Security-focused Chaos Experiments for DevSecOps Teams☆23Updated 4 months ago
- The Great Multi-Factor Authentication (MFA) Distribution Project of the Open Source Security Foundation (OpenSSF). We work to distribute …☆53Updated 2 years ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- ☆11Updated this week
- Helps you to export your kube-bench reports to multiple targets like Amazon S3 buckets with ease.☆11Updated 3 years ago
- Github Action implementation of SLSA Provenance Generation☆47Updated last week
- TACOS framework structural details☆20Updated 11 months ago
- ☆56Updated 2 years ago
- ☆11Updated last year
- PoC HTTP proxy for scale-to-zero apps via the Fly machines API☆15Updated 3 years ago
- Lambda function for verifying signed images in ECS☆33Updated 8 months ago