Projects in Awesome Lists tagged with slsa
A curated list of projects in awesome lists tagged with slsa .
https://github.com/guacsec/guac
GUAC aggregates software security metadata into a high fidelity graph database.
attestations cyclonedx cyclonedx-sbom graph in-toto sbom security slsa software-supply-chain software-supply-chain-security spdx spdx-sbom supply-chain supply-chain-analytics supply-chain-security supply-chain-visibility vex vulnerability vulnerability-management
Last synced: 14 May 2025
https://github.com/chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
attestation compliance cyclonedx devsecops in-toto license metadata-platform open-source-licensing ospo oss-compliance regulated-industry sbom sbom-discovery sbom-distribution security slsa slsa-provenance spdx supply-chain-security
Last synced: 01 May 2026
https://github.com/slsa-framework/slsa-github-generator
Language-agnostic SLSA provenance generation for Github Actions
security security-hardening security-tools slsa slsaprovenance
Last synced: 07 May 2025
https://github.com/buildsafedev/bsf
Developer-centric tool to secure your software supply chain.
hacktoberfest nix reproducibility slsa supply-chain-security
Last synced: 16 May 2025
https://github.com/oracle/macaron
Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks, detect malicious Python packages, or check conformance to frameworks, such as SLSA. Documentation:
build-system cicd docker gradle integrity-protection malware-analysis malware-detection maven npm python sbom slsa supply-chain-security
Last synced: 25 Feb 2026
https://github.com/mchmarny/s3cme
Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance
attestation cosine oidc provenance sbom slsa supply-chain-security vulnerability
Last synced: 23 Jun 2025
https://github.com/kubernetes-sigs/tejolote
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
attestation provenance sbom sigstore slsa
Last synced: 06 Apr 2026
https://github.com/sebastienrousseau/dotfiles
Declarative dotfiles for macOS, Linux, and WSL — multi-shell parity, sub-second startup, wallpaper-driven themes, SLSA-signed releases, AI/MCP-aware.
age ai bash chezmoi dotfiles fish linux macos mcp mise nix nushell oidc powershell security slsa sops workstation wsl zsh
Last synced: 31 May 2026
https://github.com/philips-labs/slsa-provenance-action
Github Action implementation of SLSA Provenance Generation
github-action github-actions hacktoberfest in-toto provenance security security-tools slsa software-supply-chain
Last synced: 06 Apr 2025
https://github.com/deislabs/image-layer-provenance
Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.
container container-image containerization containers cve docker oci oci-image oras provenance security security-audit security-tools slsa slsaprovenance vulnerabilities vulnerability vulnerability-assessment vulnerability-management
Last synced: 06 Feb 2026
https://github.com/johnbillion/action-wordpress-plugin-attestation
GitHub Action to generate an attestation for the build provenance of a plugin ZIP file on WordPress.org
github-actions slsa supply-chain-security wordpress
Last synced: 09 Jan 2026
https://github.com/jenstroeger/python-package-template
An opinionated Python package/application template repository, with SLSA and SBOM support built in, enabled for security scanners, code linters, typing, testing and code coverage monitoring, and release automation for reproducible builds.
conventional-commits python python-package release-automation reproducible-builds sbom secure-by-design security-automation slsa slsaprovenance template-repository
Last synced: 17 Jun 2025
https://github.com/docker/github-builder
Official Docker-maintained reusable GitHub Actions workflows to securely build container images
buildkit buildx docker github-actions github-actions-docker reusable-workflows sbom security security-hardening slsa slsa-provenance
Last synced: 15 Apr 2026
https://github.com/vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
cyclonedx oscal sarif sast sbom sca slsa software-transparency spdx vex vulnerability-management
Last synced: 28 Jun 2026
https://github.com/martinbaillie/ocistow
Stream, Mutate and Sign Images with AWS Lambda and ECR
aws aws-lambda cosign docker ecr oci sigstore slsa supplychain
Last synced: 18 Aug 2025
https://github.com/thomasvitale/supply-chain-security-java
Samples showing how to secure the supply chain for Java applications.
cyclonedx java sbom sigstore slsa supply-chain-security
Last synced: 15 Mar 2025
https://github.com/goreleaser/example-slsa-provenance
Example project using SLSA 3 Generic Generator with GoReleaser
goreleaser slsa slsa-framework slsa-generic-generator slsa-provenance slsa3 slsalevel3
Last synced: 18 Apr 2026
https://github.com/R00T-Kim/SCOUT
Deterministic firmware-to-exploit evidence engine. Drop a firmware blob, get hash-anchored findings with SARIF + CycloneDX SBOM + verified exploit chains.
binary-analysis cyclonedx embedded-security evidence-chain exploit-chain firmware-analysis firmware-security ghidra iot-security mcp pcode reverse-engineering sarif sbom security-automation slsa static-analysis vex vulnerability-scanner
Last synced: 24 May 2026
https://github.com/sergiomarotco/Azure-DevOps-Server-segmentation-cheat-sheet
Azure DevOps Server development system segmentation best practices
azure-devops azure-devops-server cicd-segmentation devsecops-best-practices dsomm network-segmentation security-cheat-sheets slsa supply-chain-security
Last synced: 10 Mar 2025
https://github.com/sergiomarotco/azure-devops-server-segmentation-cheat-sheet
Azure DevOps Server development system segmentation best practices
azure-devops azure-devops-server cicd-segmentation devsecops-best-practices dsomm network-segmentation security-cheat-sheets slsa supply-chain-security
Last synced: 28 Feb 2026
https://github.com/jenkinsci/slsa-plugin
A Jenkins plugin to create SLSA provenance attestations
slsa slsa-generic-generator slsa-provenance
Last synced: 17 Aug 2025
https://github.com/hashicorp/actions-go-build
Define a reproducible Go build.
build crt go reproducible slsa
Last synced: 19 Oct 2025
https://github.com/janfuhrer/podsalsa
Sample Go application project with supply chain security workflows conforms to the SLSA Build Level 3 specification
cosign goreleaser ko provenance sbom slsa supply-chain-security
Last synced: 04 Jul 2025
https://github.com/aflock-ai/cilock-action
GitHub Actions and GitLab CI integration for cilock — wrap any command or downstream action and emit a signed in-toto attestation.
attestation build-provenance ci-cd devsecops dsse github-actions gitlab-ci in-toto sigstore slsa supply-chain-security
Last synced: 26 May 2026
https://github.com/invariant-systems-ai/aiir
AI Integrity Receipts — generate, verify, and attest cryptographic receipts for commits with declared AI involvement. Release verification with SLSA-compatible VSA. Zero dependencies. Apache 2.0.
ai attestation audit compliance copilot cryptography eu-ai-act git github-actions in-toto mcp receipts security slsa supply-chain-security verification
Last synced: 17 Apr 2026
https://github.com/ozi-project/ozi
Python project packaging for Meson.
mesonbuild packaging-for-pypi packaging-python packaging-tools slsa
Last synced: 07 Sep 2025
https://github.com/open-nudge/opentemplate
All-in-one Python template. One click. Everything included.
attestations automation best-practices github-actions hardened intuitive legal linter nudging one-click performance pre-commit python reuse sbom security simple slsa template
Last synced: 26 Jun 2025
https://github.com/docker/attest
Library to create, verify, and evaluate policy for attestations on container images
attestation in-toto oci rego slsa supply-chain-security the-update-framework
Last synced: 01 Apr 2025
https://github.com/carabiner-dev/bnd
Sign and package attestations in sigstore bundles
attestation attestations intoto signature-verification signatures sigstore slsa slsa-provenance
Last synced: 27 Feb 2025
https://github.com/yandex-cloud-examples/yc-webinar-security-pipeline-2023
Материалы к вебинару «Как выстроить процесс безопасной разработки в Yandex Cloud».
cosign kms scanning-images secure-development slsa yandex-cloud yandexcloud
Last synced: 22 Feb 2026
https://github.com/kanutocd/gem-guardian
Consumer-side integrity verification for Ruby gems
artifact-verification bundler cli dependency-management developer-tools devsecops integrity-verification provenance ruby rubygems security-audit sigstore slsa software-supply-chain supply-chain-security trusted-publishing
Last synced: 23 Jun 2026
https://github.com/netresearch/enterprise-readiness-skill
Agent Skill for enterprise readiness assessment - security, quality, and automation | Claude Code compatible
agent-skills ai-agent claude-code-skill devsecops enterprise open-standard openssf security skill slsa supply-chain-security
Last synced: 25 Apr 2026
https://github.com/unidoc/unisupply
Go supply chain security analysis – finds vulnerabilities, weak maintainers, typosquatting, and CI/CD risks. SBOM + enterprise PDF reports.
audit-report ci-cd-security cyclonedx dependency-analysis go go-modules golang maintainer-analysis risk-assessment sbom sca slsa software-composition-analysis spdx supply-chain-security typosquatting
Last synced: 11 Jun 2026
https://github.com/dominikwilkowski/bronzies
A Lifesaver learning app for bronze proficiency level
highscore reactjs signals slsa teaching-tool
Last synced: 12 Apr 2025
https://github.com/hi-artem/provenance-generator-buildkite-plugin
A proof-of-concept SLSA provenance generator for Buildkite.
buildkite buildkite-plugin provenance slsa software-supply-chain
Last synced: 14 Jan 2026
https://github.com/redoubt-cysec/provenance-template
Production-ready template demonstrating supply chain security, SLSA provenance, and multi-platform distribution for Python CLIs
attestation cli devsecops github-actions homebrew provenance pypi python reproducible-builds sbom security sigstore slsa supply-chain-security template verification
Last synced: 28 Apr 2026
https://github.com/sebastienrousseau/cloudcdn.pro
The multi-tenant, AI-native CDN you can read end-to-end and deploy yourself. Sub-100ms TTFB across 300+ Cloudflare PoPs, agent-controllable over MCP (42 tools), atomic rate limiting via Durable Objects, WCAG-AA accessible, light/dark themed, 3,185 tests at 100% coverage.
accessibility ai-agents cdn cloudflare cloudflare-pages cloudflare-workers dark-mode durable-objects edge mcp-server multi-tenant openapi passkeys performance rate-limiting signed-urls slsa vectorize webauthn workers-ai
Last synced: 10 Jul 2026
https://github.com/ej-east/redoubt
Hardened container images and reusable CI workflows with cosign signing and SBOM attestation.
ci-cd container-security cosign devsecops distroless docker dockerfile ghcr github-actions hardened-images image-signing oci reusable-workflows sbom sigstore slsa supply-chain-security syft trivy vulnerability-scanning
Last synced: 07 Jun 2026
https://github.com/nelsonduarte/capa-language
A capability-centric programming language. Hand-written compiler in Python.
capability-security compiler cra cyclonedx language-design llm-security nis2 programming-language sbom slsa spdx static-analysis supply-chain-security type-system vex
Last synced: 12 Jun 2026
https://github.com/kirankotari/ossguard
One CLI to guard any OSS project with OpenSSF security best practices — bootstrap, scan, and monitor.
cli openssf ossguard sbom scorecard security slsa supply-chain
Last synced: 16 May 2026
https://github.com/salrashid123/cosign_kaniko_cloud_build
Deterministic container hashes and container signing using Cosign, Kaniko and Google Cloud Build
cicd containers cosign google-cloud google-cloud-platform slsa
Last synced: 03 Feb 2026
https://github.com/landerox/cloud-landerox-data
Reference architecture baseline for GCP data platforms (Apache Beam, BigQuery, Cloud Functions, Pub/Sub). Hybrid warehouse/lakehouse with batch + streaming, Medallion layering. Consumed by private runtime repos.
apache-beam batch-processing bigquery cloud-functions cloud-storage data-engineering data-platform dataform gcp google-cloud-dataflow iceberg lakehouse medallion-architecture opentelemetry pubsub python reference-architecture slsa streaming supply-chain-security
Last synced: 21 May 2026
https://github.com/landerox/cloud-landerox-infra
GCP Terraform baseline and reference architecture — multi-environment CI/CD, defense-in-depth (validations + Conftest + Sigstore plan attestation), Workload Identity Federation, BigQuery medallion, recipes per module. OpenSSF Best Practices silver.
artifact-registry bigquery checkov cicd cloud-run cloud-scheduler conftest devsecops gcp iam infrastructure-as-code openssf reference-architecture secret-manager sigstore slsa terraform terraform-modules workload-identity-federation
Last synced: 21 May 2026
https://github.com/victoralfred/devsec
MLSecOps security pipeline tool - automated scanning, policy enforcement, compliance mapping, and ML validation for CI/CD
cli compliance devsec golang iso27001 mlsecops opa policy-as-code sast sbom secrets-detection security slsa soc2 supply-chain-security vulnerability-scanner
Last synced: 12 Mar 2026
https://github.com/kubedoll-heavy-industries/agentcontainers
Immutable, reproducible, least-privilege runtime environments for AI agents
ai-agents containers devcontainers ebpf oci security slsa
Last synced: 18 Apr 2026
https://github.com/laugiov/security-by-design
Security by Design reference: JWT/mTLS auth, RBAC, DevSecOps pipeline (SAST/DAST/SBOM/Cosign), Kubernetes hardening. Production-grade patterns.
api-security cosign devsecops fastapi gitlab-ci helm jwt-authentication kubernetes microservices mtls owasp platform-security python rbac sast-dast sbom security-by-design slsa supply-chain-security threat-modeling
Last synced: 01 May 2026
https://github.com/forgesworn/anvil
anvil: forge-hardened npm publishing for JS/TS libraries. Reproducible builds, OIDC trusted publishing, hard pre-publish gates. Pure bash, zero dependencies.
github-actions npm npm-publish oidc provenance release reproducible-builds slsa supply-chain-security trusted-publishing
Last synced: 18 Apr 2026
https://github.com/nais/salsa-action
Sign and attest images
slsa supply supply-chain-management
Last synced: 19 Mar 2026
https://github.com/pulseengine/sigil
Sigil — Supply chain security for WebAssembly. Embedded signatures, Sigstore keyless signing, SLSA provenance. Part of the PulseEngine toolchain.
pulseengine rust sigstore slsa supply-chain-security webassembly
Last synced: 01 Apr 2026
https://github.com/sebastienrousseau/inclusio
Accessibility-first publishing engine — PDF/UA-2 + WTPDF + PDF/A-4f, C2PA + PAdES + SLSA provenance, multi-format emission, MCP server.
accessibility c2pa eaa epub jats latex lualatex mcp model-context-protocol pades pdf-a pdf-ua pdf-ua-2 provenance publishing slsa tagged-pdf tagpdf wcag wtpdf
Last synced: 10 Jul 2026
https://github.com/automatanexus/nexusedge_talos_daemon
NexusEdge Talos Daemon — I2C hardware + 44 HVAC control algorithms for Raspberry Pi controllers. SLSA L3 attested releases.
building-automation control-systems edge-computing hailo hvac i2c industrial-iot iot nexusedge pid-controller raspberry-pi rust sequent-microsystems slsa smart-building
Last synced: 11 Jun 2026
https://github.com/shenxianpeng/slsa-provenance-demo
SLSA generate and verify provenance demo
slsa slsa-generic-generator slsa-provenance slsa3
Last synced: 10 Aug 2025
https://github.com/klein-business/legal-text-mcp-de
MCP server, HTTP API & CLI for German federal/state legal texts (BGB, DSGVO, …) with canonical IDs and cite-grade source provenance.
citation-resolver claude-desktop cli command-line-interface dsgvo eur-lex fastapi gdpr german-law gesetze gesetze-im-internet legal-tech legal-texts mcp mcp-server model-context-protocol python search slsa typer
Last synced: 30 Jun 2026
https://github.com/srujantata/supply-chain-security-pipeline
Software supply chain security: Syft SBOM, Cosign keyless signing via Sigstore, SLSA Level 2 provenance, Grype CVE gating, GitHub Actions pipeline
cosign devsecops grype sbom sigstore slsa supply-chain-security syft
Last synced: 28 Jun 2026
https://github.com/cmangun/agentic-artifacts
Artifact manifests and provenance rules for integrity-preserved agent outputs
agentic-systems data-integrity data-lineage manifest provenance slsa verifiable-ai
Last synced: 03 May 2026
https://github.com/trivoallan/houba
The single front door for external container images: harden, stamp, and trace every image you run.
cli container-images containers devsecops golden-images harbor image-hardening oci provenance python slsa supply-chain-security
Last synced: 11 Jun 2026
https://github.com/aslafy-z/coreruleset-plugins-image
OWASP CRS plugins as a minimal, signed OCI image for Coraza/Envoy WAFs.
coraza coreruleset cosign envoy image-volume kubernetes modsecurity oci-image owasp-crs security slsa waf
Last synced: 18 Jun 2026
https://github.com/aflock-ai/supply-chain-attacks
Catalog of real-world software supply-chain attacks reproduced as safe harnesses, each with cilock detection demonstrated by live CI. Trivy tag-rewrite, LiteLLM .pth stealer, Nx VS Code, actions-cool hijack, Shai-Hulud npm worm, Microsoft durabletask PyPI, GitHub source disclosure.
actions-cool attack-detection attestation cve-reproduction devsecops durabletask in-toto nx-attack opa-policy secretscan shai-hulud sigstore slsa supply-chain-attack supply-chain-security
Last synced: 22 Jun 2026
https://github.com/ifimust/srsr
Really Simple Service Registry
gin go golang microservices slsa
Last synced: 26 Feb 2026
https://github.com/aenguerrand/npm-publish-slsa-two-steps
Lab repository demonstrates how to create provenance without using the npm CLI and publish a package to npmjs.com with an attached provenance file (not generated by the npm CLI)
npmjs slsa supply-chain-security
Last synced: 20 Aug 2025