{"id":13721690,"url":"https://github.com/in-toto/witness","last_synced_at":"2025-05-15T17:08:05.134Z","repository":{"id":38452685,"uuid":"434639382","full_name":"in-toto/witness","owner":"in-toto","description":"Witness is a pluggable framework for software supply chain risk management.  It automates, normalizes, and verifies software artifact provenance.","archived":false,"fork":false,"pushed_at":"2025-05-13T14:34:51.000Z","size":15949,"stargazers_count":472,"open_issues_count":76,"forks_count":66,"subscribers_count":25,"default_branch":"main","last_synced_at":"2025-05-15T10:05:56.217Z","etag":null,"topics":["attestation","security","security-tools","supply-chain","verification"],"latest_commit_sha":null,"homepage":"https://witness.dev","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/in-toto.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY-INSIGHTS.yml","support":null,"governance":"GOVERNANCE.md","roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2021-12-03T15:13:46.000Z","updated_at":"2025-05-13T14:34:54.000Z","dependencies_parsed_at":"2024-04-22T03:00:44.755Z","dependency_job_id":"dfedaae6-0abf-4725-9ee6-f61e39f34f5e","html_url":"https://github.com/in-toto/witness","commit_stats":{"total_commits":234,"total_committers":22,"mean_commits":"10.636363636363637","dds":0.7222222222222222,"last_synced_commit":"1bbd0e84e4a63f586bc852bbde7e2b629d710d92"},"previous_names":["testifysec/witness"],"tags_count":104,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/in-toto%2Fwitness","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/in-toto%2Fwitness/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/in-toto%2Fwitness/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/in-toto%2Fwitness/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/in-toto","download_url":"https://codeload.github.com/in-toto/witness/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":254384988,"owners_count":22062422,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["attestation","security","security-tools","supply-chain","verification"],"created_at":"2024-08-03T01:01:20.247Z","updated_at":"2025-05-15T17:08:00.114Z","avatar_url":"https://github.com/in-toto.png","language":"Go","funding_links":[],"categories":["Security","Go","Image Lifecycle","Supply-chain attestation"],"sub_categories":["Software Supply Chain Security","Supply Chain"],"readme":"# Witness\n[![Go Reference](https://pkg.go.dev/badge/github.com/in-toto/witness.svg)](https://pkg.go.dev/github.com/in-toto/witness) [![Go Report Card](https://goreportcard.com/badge/github.com/in-toto/witness)](https://goreportcard.com/report/github.com/in-toto/witness) [![OpenSSF Best Practices](https://www.bestpractices.dev/projects/8164/badge)](https://www.bestpractices.dev/projects/8164) [![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/in-toto/witness/badge)](https://securityscorecards.dev/viewer/?uri=github.com/in-toto/witness) [![FOSSA Status](https://app.fossa.com/api/projects/custom%2B41709%2Fgithub.com%2Fin-toto%2Fwitness.svg?type=shield\u0026issueType=license)](https://app.fossa.com/projects/custom%2B41709%2Fgithub.com%2Fin-toto%2Fwitness?ref=badge_shield\u0026issueType=license)\n\n\u003ccenter\u003e\n\n**[DOCS](https://witness.dev) •\n[CONTRIBUTING](/CONTRIBUTING.md) •\n[LICENSE](https://github.com/in-toto/witness/blob/main/LICENSE)**\n\n`bash \u003c(curl -s https://raw.githubusercontent.com/in-toto/witness/main/install-witness.sh)`\n\u003c/center\u003e\n\n\u003cimg src=\"https://raw.githubusercontent.com/in-toto/witness/main/docs/assets/logo.png\" align=\"right\"\n     alt=\"Witness project logo\" width=\"200\"\u003e\u003c/img\u003e\n\n### What does Witness do?\n✏️ **Attests** - \u003cspan class=\"tip-text\"\u003eWitness is a dynamic CLI tool that integrates into pipelines and infrastructure to create an\naudit trail for your software's entire journey through the software development lifecycle (SDLC) using the in-toto specification.\u003c/span\u003e\n\n**🧐 Verifies** - \u003cspan class=\"tip-text\"\u003eWitness also features its own policy engine with embedded support for OPA Rego, so you can\nensure that your software was handled safely from source to deployment.\u003c/span\u003e\n\n### What can you do with Witness?\n- Verify how your software was produced and what tools were used\n- Ensure that each step of the supply chain was completed by authorized users and machines\n- Detect potential tampering or malicious activity\n- Distribute attestations and policy across air gaps\n\n### Key Features\n - Integrations with GitLab, GitHub, AWS, and GCP.\n - Designed to run in both containerized and non-containerized environments **without** elevated privileges.\n - Implements the in-toto specification (including ITE-5, ITE-6 and ITE-7)\n - An embedded OPA Rego policy engine for policy enforcement\n - Keyless signing with Sigstore and SPIFFE/SPIRE\n - Integration with RFC3161 compatible timestamp authorities\n - Process tracing and process tampering prevention (Experimental)\n- Attestation storage with [Archivista](https://github.com/in-toto/archivista)\n\n### Demo\n![Demo][demo]\n\n## Quick Start\n\n### Installation\nTo install Witness, all you will need is the Witness binary. You can download this from the [releases]\n(https://github.com/testifysec/witness/releases) page or use the install script to download the\nlatest release:\n```\nbash \u003c(curl -s https://raw.githubusercontent.com/in-toto/witness/main/install-witness.sh)\n```\n\nIf you want install it manually and verify its integrity follow the instructions in the [INSTALL.md](./INSTALL.md).\n\n### Tutorials\nCheck out our Tutorials:\n\n- [Getting Started](docs/tutorials/getting-started.md)\n- [Verify an Artifact Policy](docs/tutorials/artifact-policy.md)\n- [Using Fulcio as a Key Provider](docs/tutorials/artifact-policy.md)\n\n## Media\nCheck out some of the content out in the wild that gives more detail on how the project can be used.\n\n##### [Blog/Video - Generating and Verifying Attestations With Witness](https://www.testifysec.com/blog/attestations-with-witness/)\n##### [Blog - What is a supply chain attestation, and why do I need it?](https://www.testifysec.com/blog/what-is-a-supply-chain-attestation/)\n##### [Talk - Securing the Software Supply Chain with the in-toto \u0026 SPIRE projects](https://www.youtube.com/watch?v=4lFbdkB62QI)\n##### [Talk - Securing the Software Supply Chain with SBOM and Attestation](https://www.youtube.com/watch?v=wX6aTZfpJv0)\n\n## Get Involved with the Community!\nJoin the [CNCF Slack](https://slack.cncf.io/) and join the `#in-toto-witness` channel. You might also be interested in joining the `#in-toto` channel for more general in-toto discussion, as well as\nthe `#in-toto-archivista` channel for discussion regarding the [Archivista](https://github.com/in-toto/archivista) project.\n\n## Background\nThis project was created by [TestifySec](https://www.testifysec.com/) before being donated to the in-toto project. The project is maintained by the TestifySec Open Source team and a community of contributors.\n\n[demo]: https://raw.githubusercontent.com/in-toto/witness/main/docs/assets/demo.gif \"Demo\"\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fin-toto%2Fwitness","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fin-toto%2Fwitness","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fin-toto%2Fwitness/lists"}