in-toto topic
in-toto-golang
A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.
argocd-interlace
Enabling Software Supply Chain Security Capabilities in ArgoCD
slsa-provenance-action
Github Action implementation of SLSA Provenance Generation
chainloop
Chainloop is an Open Source evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, CSAF files, QA reports, and more.
community
in-toto is a framework to secure the software supply chain.
signy
Go implementation for CNAB content trust verification using TUF, Notary, and in-toto
immunize
Pipeline for patching CVEs in container images 💉📦