{"id":23149920,"url":"https://github.com/in-toto/scai-demos","last_synced_at":"2025-06-10T15:05:01.661Z","repository":{"id":148597164,"uuid":"592585374","full_name":"in-toto/scai-demos","owner":"in-toto","description":"Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools","archived":false,"fork":false,"pushed_at":"2025-05-14T22:34:05.000Z","size":4389,"stargazers_count":18,"open_issues_count":1,"forks_count":4,"subscribers_count":5,"default_branch":"main","last_synced_at":"2025-05-14T23:27:56.025Z","etag":null,"topics":["attestations","cli","demos","software-supply-chain-security"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/in-toto.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2023-01-24T03:38:13.000Z","updated_at":"2025-05-14T22:34:03.000Z","dependencies_parsed_at":"2023-12-19T04:03:52.265Z","dependency_job_id":"d214a3aa-c42c-4742-af67-41f4c2706926","html_url":"https://github.com/in-toto/scai-demos","commit_stats":null,"previous_names":["in-toto/scai-demos"],"tags_count":3,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/in-toto%2Fscai-demos","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/in-toto%2Fscai-demos/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/in-toto%2Fscai-demos/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/in-toto%2Fscai-demos/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/in-toto","download_url":"https://codeload.github.com/in-toto/scai-demos/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/in-toto%2Fscai-demos/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":259097771,"owners_count":22804778,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["attestations","cli","demos","software-supply-chain-security"],"created_at":"2024-12-17T18:15:31.890Z","updated_at":"2025-06-10T15:05:01.618Z","avatar_url":"https://github.com/in-toto.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# in-toto SCAI Generator and Demos\n\nThe Software Supply Chain Attribute Integrity, or SCAI (pronounced \"sky\"),\nframework is a succinct data format specification for claims and evidence about\nattributes and integrity about a software artifact and its supply chain.\n\nFor more details read our [intro doc] or the full [SCAI spec doc].\n\n## In this repo\n\nThis repo provides [Go](scai-gen/) and [Python](python/) implementations of\nCLI tools for automatically generating SCAI metadata compliant with the\n[in-toto Attestation Framework].\n\nA number of sample use cases for SCAI are implemented in\n[examples/](examples/).\n\nIn addition, our Go [scai-gen](scai-gen/) CLI tool supports policy checking of\nSCAI attestations against evidence. Example policies can be found in\n[policies/](policies/).\n\nThe [SCAI specification] is hosted under the\nin-toto Attestation Framework as an attestation predicate.\n\nAll documentation can be found under [docs/](docs/).\n\n## Usage\n\nRead the [usage doc] for instructions on setup and tool invocation\nfor Python and Go environments.\n\nWe encourage you to gain a basic understanding of the [SCAI specification]\nbefore using the scai-generator CLI tools in this repo.\n\nFor a full demo of how to use the Go [scai-gen](scai-gen/) tools, read our\n[KubeCon + CloudNativeCon NA '23 doc].\n\n## Disclaimer\n\nWhile the tools in this repo are conformant to the\n[in-toto Attestation Framework], they do not generate **authenticated** SCAI\nattestations. The example use cases in this repo are only provided for\nillustrative purposes, and should not be used in production.\n\n[in-toto Attestation Framework]: https://github.com/in-toto/attestation/tree/main/spec\n[intro doc]: docs/intro.md\n[KubeCon + CloudNativeCon NA '23]: kccncna2023-demo/README.md\n[usage doc]: docs/usage.md\n[SCAI specification]: https://github.com/in-toto/attestation/blob/main/spec/predicates/scai.md\n[SCAI spec doc]: https://arxiv.org/pdf/2210.05813.pdf\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fin-toto%2Fscai-demos","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fin-toto%2Fscai-demos","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fin-toto%2Fscai-demos/lists"}