FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

slsa · GitHub Topics · GitHub

#

slsa

Here are 249 public repositories matching this topic...

Language-agnostic SLSA provenance generation for Github Actions

  • Updated Aug 7, 2026
  • Go

SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more

  • Updated Aug 28, 2026
  • Go

Developer-centric tool to secure your software supply chain.

  • Updated Dec 17, 2024
  • Go

Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks, detect malicious Python packages, or check conformance to frameworks, such as SLSA. Documentation:

  • Updated Aug 28, 2026
  • Python

Trusted builds made easy! A cloud-native software factory for building, testing, and releasing trusted software artifacts

  • Updated Aug 28, 2026
  • Go

Lockfile-first scanner for compromised npm/PyPI/Maven/Cargo/Go/RubyGems packages — OSV + curated extras feed, SLSA L3, locked-container CI

  • Updated May 5, 2026
  • Python

A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.

  • Updated Jan 28, 2024

Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance

  • Updated Apr 23, 2024
  • Go

Official Docker-maintained reusable GitHub Actions workflows to securely build container images

  • Updated Aug 21, 2026

Cross-platform dotfiles (macOS/Linux/WSL) managed by chezmoi — bash·zsh·fish·nushell parity, a fast dot CLI, wallpaper-driven themes, encrypted secrets, SLSA-signed releases, and AI/MCP-aware tooling.

  • Updated Aug 28, 2026
  • Shell

A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.

  • Updated Aug 26, 2026
  • Go

Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations

  • Updated Aug 1, 2026
  • Go

Github Action implementation of SLSA Provenance Generation

  • Updated Aug 26, 2026
  • Go

GitHub Action to generate an attestation for the build provenance of a plugin zip file on wordpress.org

  • Updated May 24, 2026

Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.

  • Updated Oct 30, 2023
  • Go

Git-native AI code provenance: records which AI agent wrote which line, signs each attribution with ed25519, stores it in your git history. Cross-agent (Claude Code, Cursor, Copilot, Codex, Windsurf, OpenCode, Gemini).

  • Updated Jun 8, 2026
  • Rust

FIPS 203 ML-KEM (CRYSTALS-Kyber) for Rust. Pure-Rust, no_std, ACVP 180/180, KyberSlash-clean, SLSA L3 + cosign-signed releases. Published on crates.io as kyberlib and kyberlib-wasm.

  • Updated Aug 25, 2026
  • Rust

All-in-one Python template. One click. Everything included.

  • Updated Aug 27, 2026
  • Shell

An opinionated Python package/application template repository, with SLSA and SBOM support built in, enabled for security scanners, code linters, typing, testing and code coverage monitoring, and release automation for reproducible builds.

  • Updated Aug 27, 2026
  • Makefile

Improve this page

Add a description, image, and links to the slsa topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the slsa topic, visit your repo's landing page and select "manage topics."

Learn more


Back | FazBrowse Home | New Git URL