Todas las etiquetas
Etiqueta del catálogo

#sigstore

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

24 registros
Con la etiqueta «sigstore»Ordenado por índice de salud
Go
98Excepcionalíndice de salud
sigstore/sigstore
Common go library shared across sigstore services and clients
Go★ 53329 ago 2026
Apache-2.029 ago 2026 · métricas 2.10.0
Go
96Excepcionalíndice de salud
sigstore/sigstore-go
Go library for Sigstore signing and verification
Go★ 9329 ago 2026
Apache-2.029 ago 2026 · métricas 2.10.0
Go
94Excepcionalíndice de salud
kubernetes-sigs/tejolote
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Go★ 7324 jul 2026
Apache-2.024 jul 2026 · métricas 2.10.0
npm
93Excepcionalíndice de salud
sigstore/sigstore-js
Code-signing for npm packages
TypeScript★ 181↓ 172M/mes31 ago 2026
Apache-2.031 ago 2026 · métricas 2.10.0
Go
90Excelenteíndice de salud
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 5421 jul 2026
Apache-2.021 jul 2026 · métricas 2.10.0
crates.io
90Excelenteíndice de salud
nolabs-ai/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 301616 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
crates.io
89Excelenteíndice de salud
always-further/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 303617 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
crates.io
89Excelenteíndice de salud
lukehinds/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 304719 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
crates.io
89Excelenteíndice de salud
prefix-dev/sigstore-rust
Sigstore implemented in Rust for Github v0.3 bundles
Rust★ 2216 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
Go
86Excelenteíndice de salud
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 024 jul 2026
Apache-2.024 jul 2026 · métricas 2.10.0
crates.io
84Excelenteíndice de salud
sebastienrousseau/rlg
Near-lock-free structured logging for Rust. 10-crate workspace: MCP server (Claude/Cursor/mcp.run), OTLP HTTP+gRPC exporter, Tower middleware, WASM + WASI 0.2 component, eBPF-style enrichers, PII redaction, log analytics, test utilities, and a jq-style CLI. Sub-µs ingest via a 65k-slot ring buffer (LMAX Disruptor).
Rust★ 4↓ 4153/mes29 ago 2026
Apache-2.029 ago 2026 · métricas 2.10.0
Go · npm
83Excelenteíndice de salud
CodesWhat/portwing
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 415 ago 2026
AGPL-3.015 ago 2026 · métricas 2.10.0
Go
83Excelenteíndice de salud
liatrio/autogov
Unified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 11 ago 2026
Apache-2.01 ago 2026 · métricas 2.10.0
npm · PyPI
80Excelenteíndice de salud
delimit-ai/delimit-mcp-server
The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.
Python · JavaScript★ 21↓ 3625/mes3 ago 2026
MIT3 ago 2026 · métricas 2.10.0
Go
77Buenoíndice de salud
carabiner-dev/bnd
Sign and package attestations in sigstore bundles
Go★ 1023 jul 2026
Apache-2.023 jul 2026 · métricas 2.10.0
PyPI · npm
77Buenoíndice de salud
creatornader/atrib
Verifiable agent actions. Every action becomes signed context for the next. Ed25519 signatures, Merkle log proofs, independently verifiable by anyone.
TypeScript · JavaScript★ 6↓ 259/mes15 jul 2026
Apache-2.015 jul 2026 · métricas 2.10.0
PyPI
73Buenoíndice de salud
b7n0de/proofbundle
Offline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth
Python★ 2↓ 6574/mes23 jul 2026
MIT23 jul 2026 · métricas 2.10.0
npm
69Buenoíndice de salud
dot-skill/skillerr
Open .skill Protocol - a sealed, inspectable package format for AI agent skills. Reference implementation: skillerr.
TypeScript · JavaScript★ 3↓ 35.3K/mes27 jul 2026
Apache-2.027 jul 2026 · métricas 2.10.0
Go · npm
67Buenoíndice de salud
codeswhat/lookout
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 316 jul 2026
Licencia propia16 jul 2026 · métricas 2.10.0
crates.io
67Buenoíndice de salud
pulseengine/sigil
Sigil — Supply chain security for WebAssembly. Embedded signatures, Sigstore keyless signing, SLSA provenance. Part of the PulseEngine toolchain.
Rust★ 05 ago 2026
Sin licencia5 ago 2026 · métricas 2.10.0
Go · npm
63Moderadoíndice de salud
daimoniac/suppline
Self-hosted Kubernetes image intake gateway: mirror → Trivy scan → CEL policy → Sigstore attestations. Admit only what passed.
Go · TypeScript★ 530 jul 2026
Apache-2.030 jul 2026 · métricas 2.10.0
Go
60Moderadoíndice de salud
olelbis/pswg
Small Go password generator CLI with shell-safe mode and signed release artifacts
Go · HTML · CSS★ 226 jul 2026
MIT26 jul 2026 · métricas 2.10.0
Packagist
59Moderadoíndice de salud
k2gl/dsse
Sign and verify DSSE (Dead Simple Signing Envelope) payloads in PHP.
PHP★ 0↓ 2480/mes26 jul 2026
MIT26 jul 2026 · métricas 2.10.0
PyPI
57Moderadoíndice de salud
astral-sh/sigstore-models
Pydantic-based, protobuf-free data models for Sigstore
Python★ 5↓ 772.8K/mes29 ago 2026
MIT29 ago 2026 · métricas 2.10.0