Projects with this topic
-
Standalone artefact signing and verification CLI for the phpboyscout ecosystem · https://sigillum.phpboyscout.uk
Updated -
Read-only mirror of cicd-sensor: An open-source runtime security monitoring tool for CI/CD environments leveraging eBPF.
Updated -
AWS KMS signing backend for gitlab.com/phpboyscout/signing — implements the Backend contract (crypto.Signer over a KMS RSA key). Blank-import to activate; reusable without the go-tool-base framework. · https://signing.phpboyscout.uk
Updated -
OpenPGP/WKD release signing & verification — a light, dependency-inverted Go library (sign via crypto.Signer backends, verify via embedded+WKD trust). Reusable without the go-tool-base framework. · https://signing.phpboyscout.uk
Updated -
Shareable sign & keys Cobra command builders for the phpboyscout signing toolchain
Updated -
A fast, minimal viewer for SPDX SBOMs: cascading documents, compliance profiles (NTIA, BSI TR-03183), VEX overlay. Client-side, files never leave your machine.
Updated -
Toolchain image for the Coroboros security gates.
UpdatedUpdated -
A fast, minimal viewer for Open Component Model deliveries: CTF archives, embedded SBOMs, client-side signature verification, OCI registry browsing.
Updated -
-
A comprehensive guide to software supply chain security. This open-source manuscript provides security professionals and developers with practical strategies to defend against ecosystem threats.
Updated -
Kubernetes-native Helm auditor for supply chain security, aggregating SBOM, vulnerability, and provenance data.
Updated