全部标签
目录标签

#slsa

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

5 条记录
标签为“slsa”按健康指数排序
Go
85优秀健康指数
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 5702026年7月16日
Apache-2.02026年7月16日 · 指标 1.13.0
Go · PyPI
71良好健康指数
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 32026年7月16日
MIT2026年7月16日 · 指标 1.13.0
PyPI
68中等健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
Go
66中等健康指数
carabiner-dev/bnd
Sign and package attestations in sigstore bundles
Go★ 102026年7月23日
Apache-2.02026年7月23日 · 指标 1.13.0
Go
56中等健康指数
vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Open Policy Agent · Go★ 25↓ 0/月2026年7月14日
自定义许可证2026年7月14日 · 指标 1.13.0