Alle Tags
Katalog-Tag

#slsa

Alle Repositories im öffentlichen Register, die dieses Tag tragen — aus ihren GitHub-Topics oder den von ihren Paket-Registries veröffentlichten Schlagwörtern. Die Gesundheit wird nach derselben versionierten Methodik gemessen wie im übrigen Register.

11 Einträge
Getaggt als „slsa“Geordnet nach Gesundheitsindex
Go
98AußergewöhnlichGesundheitsindex
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016. Juli 2026
Apache-2.016. Juli 2026 · Metriken 2.10.0
Go
94AußergewöhnlichGesundheitsindex
kubernetes-sigs/tejolote
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Go★ 7324. Juli 2026
Apache-2.024. Juli 2026 · Metriken 2.10.0
PyPI · crates.io · Go +1
92ExzellentGesundheitsindex
in-toto/attestation
in-toto Attestation Framework
Rust★ 369↓ 44.4K/Monat29. Aug. 2026
Eigene Lizenz29. Aug. 2026 · Metriken 2.10.0
npm
86ExzellentGesundheitsindex
blamejs/blamejs
The Node framework that owns its stack.
JavaScript★ 3↓ 15.2K/Monat22. Aug. 2026
Apache-2.022. Aug. 2026 · Metriken 2.10.0
Go · PyPI
86ExzellentGesundheitsindex
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 316. Juli 2026
MIT16. Juli 2026 · Metriken 2.10.0
Go
83ExzellentGesundheitsindex
liatrio/autogov
Unified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 11. Aug. 2026
Apache-2.01. Aug. 2026 · Metriken 2.10.0
PyPI
78GutGesundheitsindex
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1.928/Monat17. Juli 2026
Apache-2.017. Juli 2026 · Metriken 2.10.0
Go
77GutGesundheitsindex
carabiner-dev/bnd
Sign and package attestations in sigstore bundles
Go★ 1023. Juli 2026
Apache-2.023. Juli 2026 · Metriken 2.10.0
Go
71GutGesundheitsindex
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 255. Sept. 2026
Eigene Lizenz5. Sept. 2026 · Metriken 2.10.0
crates.io
67GutGesundheitsindex
pulseengine/sigil
Sigil — Supply chain security for WebAssembly. Embedded signatures, Sigstore keyless signing, SLSA provenance. Part of the PulseEngine toolchain.
Rust★ 05. Aug. 2026
Keine Lizenz5. Aug. 2026 · Metriken 2.10.0
Packagist
59MittelGesundheitsindex
k2gl/dsse
Sign and verify DSSE (Dead Simple Signing Envelope) payloads in PHP.
PHP★ 0↓ 2.480/Monat26. Juli 2026
MIT26. Juli 2026 · Metriken 2.10.0