Go98Exceptionalhealth index
chainloop-dev/chainloopSDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 570Jul 16, 2026
crates.io96Exceptionalhealth index
Rust★ 174Aug 19, 2026
Go94Exceptionalhealth index
kubernetes-sigs/tejoloteA highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Go★ 73Jul 24, 2026
npm93Exceptionalhealth index
TypeScript★ 5,836↓ 207M/moAug 28, 2026
PyPI · crates.io · Go +192Excellenthealth index
Rust★ 369↓ 44.4K/moAug 29, 2026
PyPI90Excellenthealth index
Python★ 113Jul 17, 2026
Go90Excellenthealth index
Go★ 54Jul 21, 2026
PyPI86Excellenthealth index

agentrust-io/trace-specTRACE: Trust Runtime Attestation and Compliance Evidence. Open attestation standard for agentic AI governance.
Python★ 24↓ 142.9K/moSep 6, 2026
PyPI86Excellenthealth index

vaaraio/vaaraAccountable Autonomy: open-source evidence layer that gates every AI agent tool call against your policy and writes a hash-chained record an auditor verifies offline, without trusting you. Root-agnostic; binds to TPM 2.0 / SEV-SNP when present. Your environment, no SaaS, no telemetry. AGPL-3.0.
Python★ 11↓ 6,460/moAug 22, 2026
crates.io · PyPI · npm +184Excellenthealth index
Rust · JavaScript★ 40↓ 48.5K/moJul 23, 2026
crates.io84Excellenthealth index

tkhq/rust-sdkRepository containing Rust tooling to interact with the Turnkey API
Rust★ 40↓ 376.6K/moSep 5, 2026
crates.io83Excellenthealth index
Azure/corimRust Implementation of CoRIM (Concise Reference Integrity Manifest)
Rust★ 3↓ 5,443/moJul 31, 2026
Go83Excellenthealth index
liatrio/autogovUnified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 1Aug 1, 2026
npm · PyPI80Excellenthealth index
delimit-ai/delimit-mcp-serverThe merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.
Python · JavaScript★ 21↓ 3,625/moAug 3, 2026
npm · Go · crates.io77Goodhealth index
Rust · Solidity★ 56↓ 240/moJul 18, 2026
Go★ 10Jul 23, 2026
npm · crates.io · PyPI77Goodhealth index
Rust · Kotlin★ 10↓ 25.8K/moAug 20, 2026
msaleme/red-team-blue-team-agent-fabric540 security tests for AI agent systems — MCP, A2A, x402/L402, decision governance, benchmark integrity, skill supply chain. AIUC-1 pre-cert, NIST AI 800-2 aligned, MCP tool-poisoning reproduction. v4.9.1
Python★ 20↓ 667/moJul 20, 2026
b7n0de/proofbundleOffline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth
Python★ 2↓ 6,574/moJul 23, 2026
crates.io73Goodhealth index
Rust★ 18↓ 23.7K/moJul 24, 2026

a-sit-plus/signumKotlin Multiplatform Crypto/PKI/ASN.1 Library with Attestation and Hardware-Backed Crypto Support on Mobile
Kotlin★ 195Sep 2, 2026
crates.io69Goodhealth index
auths-dev/authsLocal first, air-gapped identity for individuals, AI agents, organizations, with permissioning. Docs below are for contributors.
Rust★ 3↓ 1,367/moJul 29, 2026
dot-skill/skillerrOpen .skill Protocol - a sealed, inspectable package format for AI agent skills. Reference implementation: skillerr.
TypeScript · JavaScript★ 3↓ 35.3K/moJul 27, 2026
agentrust-io/agent-manifestAgent Manifest SDK. Hardware-anchors all 10 artifacts defining an agent at deployment. Python and TypeScript.
Python★ 11↓ 4,734/moAug 2, 2026
RubyGems65Goodhealth index
Ruby★ 11Jul 26, 2026
PyPI63Moderatehealth index
QWED-AI/qwed-ucpVerification for Universal Commerce Protocol (UCP) transactions — Deterministic verification layer for UCP checkouts: catches math, state, and schema errors before payment.
Python★ 0Jul 30, 2026
Packagist59Moderatehealth index
k2gl/dsseSign and verify DSSE (Dead Simple Signing Envelope) payloads in PHP.
PHP★ 0↓ 2,480/moJul 26, 2026
npm · PyPI59Moderatehealth index
orangecheck/oc-packagesMonorepo for the @orangecheck/* npm packages + the orangecheck Python SDK. SDK, gate middleware, React bindings, wallet adapter, CLI, Strfry relay filter, airdrop-gate.
TypeScript★ 0↓ 5,998/moJul 27, 2026
npm · Go57Moderatehealth index
daily-nerd/vitniThe verifiable trail of agent actions — signed, tamper-evident execution receipts for AI agents (MCP & A2A).
Go · TypeScript · JavaScript★ 1↓ 372/moJul 17, 2026
Verdifax/verdifax-verifyCryptographic attestation infrastructure for high-stakes AI decisions. Every governed execution produces a sealed, independently-verifiable manifest hash. USPTO patent + trademark filed.
Go★ 0Jul 22, 2026