Pinned Loading
Repositories
Showing 10 of 43 repositories
- archivista Public
Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for software artifacts.
- witness Public
Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
- friends Public
Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.
- in-toto-golang Public
A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.
- attestation-verifier Public
Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts
Top languages
Loading…
Most used topics
Loading…