slsa
Here are 19 public repositories matching this topic...
Ensignia Provenance Upload Action
-
Updated
Jun 1, 2023 - Go
A demonstration of how GoReleaser can help us to make software supply chain more secure by using bunch of tools such as cosign, syft, grype, slsa-provenance
-
Updated
Feb 10, 2022 - Go
SLSA level 3 action
-
Updated
Apr 26, 2024 - Go
A proof-of-concept SLSA provenance generator for Buildkite.
-
Updated
Oct 20, 2021 - Go
Sample Go application project with supply chain security workflows conforms to the SLSA Build Level 3 specification
-
Updated
Oct 14, 2024 - Go
Stream, Mutate and Sign Images with AWS Lambda and ECR
-
Updated
Oct 28, 2021 - Go
A demonstration of showing how to use 💃SLSA 3 Generic Generator with GoReleaser to release artifacts while generating signed SLSA provenance
-
Updated
Oct 26, 2023 - Go
Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.
-
Updated
Oct 30, 2023 - Go
Library to create, verify, and evaluate policy for attestations on container images
-
Updated
Nov 15, 2024 - Go
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
-
Updated
Nov 15, 2024 - Go
Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance
-
Updated
Apr 23, 2024 - Go
Developer-centric tool to secure your software supply chain.
-
Updated
Nov 14, 2024 - Go
Github Action implementation of SLSA Provenance Generation
-
Updated
Nov 11, 2024 - Go
Chainloop is an Open Source evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, CSAF files, QA reports, and more.
-
Updated
Nov 15, 2024 - Go
Language-agnostic SLSA provenance generation for Github Actions
-
Updated
Nov 4, 2024 - Go
Improve this page
Add a description, image, and links to the slsa topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the slsa topic, visit your repo's landing page and select "manage topics."