slsa topic

List slsa repositories

slsa-github-generator

381
Stars
115
Forks
Watchers

Language-agnostic SLSA provenance generation for Github Actions

ocistow

18
Stars
1
Forks
Watchers

Stream, Mutate and Sign Images with AWS Lambda and ECR

python-package-template

33
Stars
11
Forks
Watchers

An opinionated Python package/application template repository, with SLSA and SBOM support built in, enabled for security scanners, code linters, typing, testing and code coverage monitoring, and relea...

slsa-provenance-action

45
Stars
18
Forks
Watchers

Github Action implementation of SLSA Provenance Generation

image-layer-provenance

40
Stars
2
Forks
Watchers

Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.

s3cme

46
Stars
8
Forks
Watchers

Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance

Software-Supply-Chain-Security

114
Stars
12
Forks
Watchers

A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the...

chainloop

318
Stars
24
Forks
Watchers

Chainloop is an Open Source evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, CSAF files, QA reports, and more.

macaron

109
Stars
17
Forks
Watchers

Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks or che...

tejolote

55
Stars
9
Forks
Watchers

A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.