philips-labs / slsa-provenance-actionView external linksLinks
Github Action implementation of SLSA Provenance Generation
☆50Feb 9, 2026Updated last week
Alternatives and similar repositories for slsa-provenance-action
Users that are interested in slsa-provenance-action are comparing it to the libraries listed below
Sorting:
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl…☆11Jan 26, 2026Updated 3 weeks ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Nov 1, 2022Updated 3 years ago
- GitHub actions for the chainguard-images☆21Feb 9, 2026Updated last week
- Submit SBOMs to GitHub's dependency submission API☆18Dec 4, 2025Updated 2 months ago
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆45Oct 30, 2023Updated 2 years ago
- A proof-of-concept SLSA provenance generator for Jenkins☆24Jul 29, 2024Updated last year
- Integrates Spiffe and Vault to have secretless authentication☆97Jan 19, 2026Updated 3 weeks ago
- ☆11Nov 11, 2022Updated 3 years ago
- SLSA level 3 action☆11Apr 26, 2024Updated last year
- A docker CLI plugin for verifying signed attestations on images☆13Oct 27, 2023Updated 2 years ago
- Lambda function for verifying signed images in ECS☆36Mar 9, 2024Updated last year
- Example repository that demonstrates a supply chain security workflow using Syft, Grype, Cosign☆12Sep 15, 2021Updated 4 years ago
- Generates SPDX bill-of-material files from a package input and license scan☆13Apr 15, 2024Updated last year
- To manage Docker Content Trust and Notary certificates☆13Updated this week
- Comparison of Chainguard Images to others☆21Updated this week
- ☆58Jun 1, 2022Updated 3 years ago
- ☆20Mar 5, 2022Updated 3 years ago
- Docker CI scripts☆12Nov 24, 2025Updated 2 months ago
- A specification for signing methods and formats used by Secure Systems Lab projects.☆94Nov 10, 2025Updated 3 months ago
- Open Policy Agent WebAssembly Go SDK☆21Jan 8, 2026Updated last month
- GitHub action to produce a SBOM report from a given Black Duck project☆12Feb 5, 2026Updated last week
- Pre-commit git hooks for Open Policy Agent (OPA) and Rego development☆68Jul 6, 2025Updated 7 months ago
- ☆255Updated this week
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆345Feb 7, 2026Updated last week
- Enable Falco to read audit logs from EKS☆11Dec 13, 2020Updated 5 years ago
- Kubernetes in Docker on Travis-CI☆44Jul 5, 2019Updated 6 years ago
- An example repo demonstrating keyless signing with Github Actions☆11May 24, 2022Updated 3 years ago
- Repository characteristics☆14Updated this week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆514Updated this week
- vexctl is a tool to attest VEX impact statements☆45Mar 27, 2023Updated 2 years ago
- Sharing software supply chain security open source projects☆53Dec 19, 2022Updated 3 years ago
- A kubectl plugin to run kubectl macro that wraps a set of kubectl calls into one command to be run many times.☆11Jun 28, 2021Updated 4 years ago
- Linux agent used to submit realtime SBOMs and dependency usage information to EdgeBit☆15Jan 24, 2025Updated last year
- Build and publish Docker images, run builds/tasks within Docker containers or on remote hosts.☆16Updated this week
- A Kubewarden Policy that verifies all the signatures of the container images referenced by a Pod☆13Jan 20, 2026Updated 3 weeks ago
- create issues from a syndication feed (RSS or Atom).☆14Updated this week
- A practice repo to collect examples of using tekton with kubernetes☆11May 18, 2020Updated 5 years ago
- A configurable and flexible admission controller toolkit for Kubernetes built in Go and extensible with Go.☆13Sep 29, 2023Updated 2 years ago
- Multi-arch templates for OpenFaaS☆12Sep 11, 2020Updated 5 years ago