in-toto
in-toto
in-toto
in-toto is a framework to protect supply chain integrity.
witness
Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
in-toto-golang
A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.
attestation
in-toto Attestation Framework
demo
Securing Alice's, Bob's and Carl's software supply chain using in-toto
in-toto-rs
A rust implementation of in-toto
community
in-toto is a framework to secure the software supply chain.
scai-demos
Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools