spdx / sbom-landscapeLinks
SPDX SBOM Landscape
☆16Updated 2 years ago
Alternatives and similar repositories for sbom-landscape
Users that are interested in sbom-landscape are comparing it to the libraries listed below
Sorting:
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆70Updated this week
- depstat is a dependency analyzer for Go modules enabled projects. It runs as part of the Kubernetes CI pipeline to help evaluate dependen…☆37Updated last year
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆45Updated 2 years ago
- Operator deploying the Observatorium project☆14Updated last year
- Service implementation for a Kubernetes Dynamic Webhook controller for interacting with Anchore☆65Updated this week
- A Kubewarden Policy that verifies all the signatures of the container images referenced by a Pod☆13Updated this week
- ☆113Updated 7 months ago
- JSON query library, based on Rego☆18Updated 5 years ago
- Sigstore's Protocol Buffer specifications☆33Updated this week
- Open Source declarative disk configuration system for Kubernetes☆40Updated 2 years ago
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆33Updated 7 months ago
- Cloud Storage Kubernetes Operator with Go and Operator SDK☆12Updated 5 years ago
- Helm Chart for deploying GUAC☆18Updated 6 months ago
- Integrates Spiffe and Vault to have secretless authentication☆96Updated this week
- Sigstore user stories☆30Updated 2 years ago
- A High-Availability distribution of Knative.☆20Updated last year
- GitVote is a GitHub application that allows holding a vote on issues and pull requests☆126Updated this week
- ☆64Updated last year
- ☆26Updated this week
- ☆14Updated 2 years ago
- ☆33Updated 10 months ago
- To manage Docker Content Trust and Notary certificates☆13Updated last week
- ☆58Updated 3 years ago
- A Kubernetes admission controller driven by open-feature☆14Updated 2 years ago
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆142Updated last week
- Linux agent used to submit realtime SBOMs and dependency usage information to EdgeBit☆14Updated 10 months ago
- 🏆 CNCF Community Awards☆26Updated last month
- ☆20Updated 6 months ago
- A starter repo to donate to Kubernetes-sigs so the community can own and iterate on stories over time, with issue tracking, as we close o…☆13Updated 3 years ago
- A data access control framework for Open Policy Agent☆37Updated last year