全部标签
目录标签

#slsa

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

11 条记录
标签为“slsa”按健康指数排序
Go
98卓越健康指数
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 5702026年7月16日
Apache-2.02026年7月16日 · 指标 2.10.0
Go
94卓越健康指数
kubernetes-sigs/tejolote
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Go★ 732026年7月24日
Apache-2.02026年7月24日 · 指标 2.10.0
PyPI · crates.io · Go +1
92优秀健康指数
in-toto/attestation
in-toto Attestation Framework
Rust★ 369↓ 44.4K/月2026年8月29日
自定义许可证2026年8月29日 · 指标 2.10.0
npm
86优秀健康指数
blamejs/blamejs
The Node framework that owns its stack.
JavaScript★ 3↓ 15.2K/月2026年8月22日
Apache-2.02026年8月22日 · 指标 2.10.0
Go · PyPI
86优秀健康指数
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 32026年7月16日
MIT2026年7月16日 · 指标 2.10.0
Go
83优秀健康指数
liatrio/autogov
Unified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 12026年8月1日
Apache-2.02026年8月1日 · 指标 2.10.0
PyPI
78良好健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
Go
77良好健康指数
carabiner-dev/bnd
Sign and package attestations in sigstore bundles
Go★ 102026年7月23日
Apache-2.02026年7月23日 · 指标 2.10.0
Go
71良好健康指数
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 252026年9月5日
自定义许可证2026年9月5日 · 指标 2.10.0
crates.io
67良好健康指数
pulseengine/sigil
Sigil — Supply chain security for WebAssembly. Embedded signatures, Sigstore keyless signing, SLSA provenance. Part of the PulseEngine toolchain.
Rust★ 02026年8月5日
无许可证2026年8月5日 · 指标 2.10.0
Packagist
59中等健康指数
k2gl/dsse
Sign and verify DSSE (Dead Simple Signing Envelope) payloads in PHP.
PHP★ 0↓ 2,480/月2026年7月26日
MIT2026年7月26日 · 指标 2.10.0