sozercan / guac-ai-moleLinks
π₯ Inspect and understand an organization's software supply chain using AI to enable stakeholders to make actionable decisions about software supply chain security
β21Updated last year
Alternatives and similar repositories for guac-ai-mole
Users that are interested in guac-ai-mole are comparing it to the libraries listed below
Sorting:
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworksβ33Updated 8 months ago
- Visualizer for GUACβ29Updated 3 weeks ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for soβ¦β103Updated this week
- β71Updated last month
- Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable suppβ¦β152Updated 3 weeks ago
- Helm Chart for deploying GUACβ18Updated 7 months ago
- A tool to create, transform and attest VEX metadataβ170Updated this week
- Example CLI project to demo API architecture and protobom libraryβ23Updated 3 weeks ago
- Artifact Ratification Framework (CNCF Sandbox)β281Updated 3 weeks ago
- CLOMonitor is a tool that periodically checks open source projects repositories to verify they meet certain project health best practicesβ144Updated last week
- Generate a score for your sbom to understand if it will actually be useful.β236Updated last year
- A specification for signing methods and formats used by Secure Systems Lab projects.β90Updated 2 months ago
- A CLI tool for creating secure by design/default source repos.β28Updated last year
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.β70Updated 2 weeks ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI toolsβ18Updated 3 weeks ago
- β253Updated 2 weeks ago
- vexctl is a tool to attest VEX impact statementsβ45Updated 2 years ago
- Cross tooling and interoperability specificationsβ174Updated 7 months ago
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.β70Updated 3 weeks ago
- Helm charts for sigstore projectβ85Updated this week
- Supply Chain Security in Tekton Pipelinesβ265Updated this week
- β64Updated last year
- OpenVEX Specificationβ163Updated 7 months ago
- TUF repository for Sigstore trust rootβ117Updated this week
- β16Updated 4 months ago
- sigstore the hard way!β116Updated 5 months ago
- sigstore installation walkthrough, localβ62Updated last month
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuouslyβ¦β223Updated 7 months ago
- Go implementation of witnessβ42Updated this week
- A utility to generate SPDX-compliant Bill of Materials manifestsβ431Updated 3 weeks ago