All tags
Catalogue tag

#slsa

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

11 records
Tagged “slsa”Ranked by health index
Go
98Exceptionalhealth index
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 570Jul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 2.10.0
Go
94Exceptionalhealth index
kubernetes-sigs/tejolote
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Go★ 73Jul 24, 2026
Apache-2.0Jul 24, 2026 · metrics 2.10.0
PyPI · crates.io · Go +1
92Excellenthealth index
in-toto/attestation
in-toto Attestation Framework
Rust★ 369↓ 44.4K/moAug 29, 2026
Custom licenseAug 29, 2026 · metrics 2.10.0
npm
86Excellenthealth index
blamejs/blamejs
The Node framework that owns its stack.
JavaScript★ 3↓ 15.2K/moAug 22, 2026
Apache-2.0Aug 22, 2026 · metrics 2.10.0
Go · PyPI
86Excellenthealth index
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 3Jul 16, 2026
MITJul 16, 2026 · metrics 2.10.0
Go
83Excellenthealth index
liatrio/autogov
Unified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 1Aug 1, 2026
Apache-2.0Aug 1, 2026 · metrics 2.10.0
PyPI
78Goodhealth index
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
Go
77Goodhealth index
carabiner-dev/bnd
Sign and package attestations in sigstore bundles
Go★ 10Jul 23, 2026
Apache-2.0Jul 23, 2026 · metrics 2.10.0
Go
71Goodhealth index
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 25Sep 5, 2026
Custom licenseSep 5, 2026 · metrics 2.10.0
crates.io
67Goodhealth index
pulseengine/sigil
Sigil — Supply chain security for WebAssembly. Embedded signatures, Sigstore keyless signing, SLSA provenance. Part of the PulseEngine toolchain.
Rust★ 0Aug 5, 2026
No licenseAug 5, 2026 · metrics 2.10.0
Packagist
59Moderatehealth index
k2gl/dsse
Sign and verify DSSE (Dead Simple Signing Envelope) payloads in PHP.
PHP★ 0↓ 2,480/moJul 26, 2026
MITJul 26, 2026 · metrics 2.10.0