slsa-framework / oss-na24-slsa-workshopLinks
☆10Updated last year
Alternatives and similar repositories for oss-na24-slsa-workshop
Users that are interested in oss-na24-slsa-workshop are comparing it to the libraries listed below
Sorting:
- SLSA Proposals☆9Updated last year
- Sigstore's Protocol Buffer specifications☆32Updated last week
- Log monitor for Rekor to verify immutability and monitor entries☆34Updated this week
- Search Rekor for entries☆34Updated 2 months ago
- A specification for signing methods and formats used by Secure Systems Lab projects.☆78Updated 8 months ago
- This repository stores meetings minutes for the SPDX project☆30Updated this week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆31Updated last month
- Supply Chain Query Tool☆13Updated 3 years ago
- A CLI tool for creating secure by design/default source repos.☆25Updated 10 months ago
- TUF repository for Sigstore trust root☆103Updated this week
- ☆56Updated 3 years ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆35Updated 3 weeks ago
- ☆29Updated this week
- A proof-of-concept SLSA provenance generator for Jenkins☆23Updated 10 months ago
- A Jenkins plugin to track steps and create in-toto link metadata☆11Updated 11 months ago
- A TUF repository and signing tool☆35Updated this week
- Action for generating attestations for workflow artifacts☆49Updated this week
- Helm charts for verifying artifact attestations in Kubernetes☆13Updated this week
- Cryptographic and general-purpose routines for Golang Secure Systems Lab projects at NYU☆27Updated 3 weeks ago
- ☆20Updated this week
- Purpose-built security agent for hosted runners☆36Updated 3 weeks ago
- Technical Advisory Council☆124Updated last week
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 4 months ago
- in-toto Enhancements☆19Updated 3 months ago
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Updated last year
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Updated 2 years ago
- Go library for Sigstore signing and verification☆68Updated this week
- Go module to generate and transform VEX documents☆42Updated 2 weeks ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆92Updated last week
- ☆62Updated 10 months ago