An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with slsa

A curated list of projects in awesome lists tagged with slsa .

https://github.com/slsa-framework/slsa-github-generator

Language-agnostic SLSA provenance generation for Github Actions

security security-hardening security-tools slsa slsaprovenance

Last synced: 07 May 2025

https://github.com/buildsafedev/bsf

Developer-centric tool to secure your software supply chain.

hacktoberfest nix reproducibility slsa supply-chain-security

Last synced: 16 May 2025

https://github.com/oracle/macaron

Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks, detect malicious Python packages, or check conformance to frameworks, such as SLSA. Documentation:

build-system cicd docker gradle integrity-protection malware-analysis malware-detection maven npm python sbom slsa supply-chain-security

Last synced: 25 Feb 2026

https://github.com/mchmarny/s3cme

Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance

attestation cosine oidc provenance sbom slsa supply-chain-security vulnerability

Last synced: 23 Jun 2025

https://github.com/kubernetes-sigs/tejolote

A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.

attestation provenance sbom sigstore slsa

Last synced: 06 Apr 2026

https://github.com/sebastienrousseau/dotfiles

Declarative dotfiles for macOS, Linux, and WSL — multi-shell parity, sub-second startup, wallpaper-driven themes, SLSA-signed releases, AI/MCP-aware.

age ai bash chezmoi dotfiles fish linux macos mcp mise nix nushell oidc powershell security slsa sops workstation wsl zsh

Last synced: 31 May 2026

https://github.com/johnbillion/action-wordpress-plugin-attestation

GitHub Action to generate an attestation for the build provenance of a plugin ZIP file on WordPress.org

github-actions slsa supply-chain-security wordpress

Last synced: 09 Jan 2026

https://github.com/jenstroeger/python-package-template

An opinionated Python package/application template repository, with SLSA and SBOM support built in, enabled for security scanners, code linters, typing, testing and code coverage monitoring, and release automation for reproducible builds.

conventional-commits python python-package release-automation reproducible-builds sbom secure-by-design security-automation slsa slsaprovenance template-repository

Last synced: 17 Jun 2025

https://github.com/docker/github-builder

Official Docker-maintained reusable GitHub Actions workflows to securely build container images

buildkit buildx docker github-actions github-actions-docker reusable-workflows sbom security security-hardening slsa slsa-provenance

Last synced: 15 Apr 2026

https://github.com/vulnetix/cli

Automate vulnerability triage which prioritizes remediation over discovery

cyclonedx oscal sarif sast sbom sca slsa software-transparency spdx vex vulnerability-management

Last synced: 28 Jun 2026

https://github.com/martinbaillie/ocistow

Stream, Mutate and Sign Images with AWS Lambda and ECR

aws aws-lambda cosign docker ecr oci sigstore slsa supplychain

Last synced: 18 Aug 2025

https://github.com/thomasvitale/supply-chain-security-java

Samples showing how to secure the supply chain for Java applications.

cyclonedx java sbom sigstore slsa supply-chain-security

Last synced: 15 Mar 2025

https://github.com/goreleaser/example-slsa-provenance

Example project using SLSA 3 Generic Generator with GoReleaser

goreleaser slsa slsa-framework slsa-generic-generator slsa-provenance slsa3 slsalevel3

Last synced: 18 Apr 2026

https://github.com/googlecloudplatform/aactl

Google Container Analysis data import utility, supports OSS vulnerability scanner reports, SLSA provenance and sigstore attestations.

artifact attestations build container cosign gcb gcp import predicate sbom sigstore slsa

Last synced: 20 Oct 2025

https://github.com/R00T-Kim/SCOUT

Deterministic firmware-to-exploit evidence engine. Drop a firmware blob, get hash-anchored findings with SARIF + CycloneDX SBOM + verified exploit chains.

binary-analysis cyclonedx embedded-security evidence-chain exploit-chain firmware-analysis firmware-security ghidra iot-security mcp pcode reverse-engineering sarif sbom security-automation slsa static-analysis vex vulnerability-scanner

Last synced: 24 May 2026

https://github.com/jenkinsci/slsa-plugin

A Jenkins plugin to create SLSA provenance attestations

slsa slsa-generic-generator slsa-provenance

Last synced: 17 Aug 2025

https://github.com/hashicorp/actions-go-build

Define a reproducible Go build.

build crt go reproducible slsa

Last synced: 19 Oct 2025

https://github.com/janfuhrer/podsalsa

Sample Go application project with supply chain security workflows conforms to the SLSA Build Level 3 specification

cosign goreleaser ko provenance sbom slsa supply-chain-security

Last synced: 04 Jul 2025

https://github.com/aflock-ai/cilock-action

GitHub Actions and GitLab CI integration for cilock — wrap any command or downstream action and emit a signed in-toto attestation.

attestation build-provenance ci-cd devsecops dsse github-actions gitlab-ci in-toto sigstore slsa supply-chain-security

Last synced: 26 May 2026

https://github.com/invariant-systems-ai/aiir

AI Integrity Receipts — generate, verify, and attest cryptographic receipts for commits with declared AI involvement. Release verification with SLSA-compatible VSA. Zero dependencies. Apache 2.0.

ai attestation audit compliance copilot cryptography eu-ai-act git github-actions in-toto mcp receipts security slsa supply-chain-security verification

Last synced: 17 Apr 2026

https://github.com/ozi-project/ozi

Python project packaging for Meson.

mesonbuild packaging-for-pypi packaging-python packaging-tools slsa

Last synced: 07 Sep 2025

https://github.com/docker/attest

Library to create, verify, and evaluate policy for attestations on container images

attestation in-toto oci rego slsa supply-chain-security the-update-framework

Last synced: 01 Apr 2025

https://github.com/carabiner-dev/bnd

Sign and package attestations in sigstore bundles

attestation attestations intoto signature-verification signatures sigstore slsa slsa-provenance

Last synced: 27 Feb 2025

https://github.com/yandex-cloud-examples/yc-webinar-security-pipeline-2023

Материалы к вебинару «Как выстроить процесс безопасной разработки в Yandex Cloud».

cosign kms scanning-images secure-development slsa yandex-cloud yandexcloud

Last synced: 22 Feb 2026

https://github.com/andros21/rustracer

rustracer - a multi-threaded raytracer in pure rust

cargo clap cosign coverage cue rayon raytracing rust slsa yaml

Last synced: 13 Apr 2025

https://github.com/netresearch/enterprise-readiness-skill

Agent Skill for enterprise readiness assessment - security, quality, and automation | Claude Code compatible

agent-skills ai-agent claude-code-skill devsecops enterprise open-standard openssf security skill slsa supply-chain-security

Last synced: 25 Apr 2026

https://github.com/unidoc/unisupply

Go supply chain security analysis – finds vulnerabilities, weak maintainers, typosquatting, and CI/CD risks. SBOM + enterprise PDF reports.

audit-report ci-cd-security cyclonedx dependency-analysis go go-modules golang maintainer-analysis risk-assessment sbom sca slsa software-composition-analysis spdx supply-chain-security typosquatting

Last synced: 11 Jun 2026

https://github.com/dominikwilkowski/bronzies

A Lifesaver learning app for bronze proficiency level

highscore reactjs signals slsa teaching-tool

Last synced: 12 Apr 2025

https://github.com/hi-artem/provenance-generator-buildkite-plugin

A proof-of-concept SLSA provenance generator for Buildkite.

buildkite buildkite-plugin provenance slsa software-supply-chain

Last synced: 14 Jan 2026

https://github.com/redoubt-cysec/provenance-template

Production-ready template demonstrating supply chain security, SLSA provenance, and multi-platform distribution for Python CLIs

attestation cli devsecops github-actions homebrew provenance pypi python reproducible-builds sbom security sigstore slsa supply-chain-security template verification

Last synced: 28 Apr 2026

https://github.com/sebastienrousseau/cloudcdn.pro

The multi-tenant, AI-native CDN you can read end-to-end and deploy yourself. Sub-100ms TTFB across 300+ Cloudflare PoPs, agent-controllable over MCP (42 tools), atomic rate limiting via Durable Objects, WCAG-AA accessible, light/dark themed, 3,185 tests at 100% coverage.

accessibility ai-agents cdn cloudflare cloudflare-pages cloudflare-workers dark-mode durable-objects edge mcp-server multi-tenant openapi passkeys performance rate-limiting signed-urls slsa vectorize webauthn workers-ai

Last synced: 10 Jul 2026

https://github.com/kirankotari/ossguard

One CLI to guard any OSS project with OpenSSF security best practices — bootstrap, scan, and monitor.

cli openssf ossguard sbom scorecard security slsa supply-chain

Last synced: 16 May 2026

https://github.com/salrashid123/cosign_kaniko_cloud_build

Deterministic container hashes and container signing using Cosign, Kaniko and Google Cloud Build

cicd containers cosign google-cloud google-cloud-platform slsa

Last synced: 03 Feb 2026

https://github.com/landerox/cloud-landerox-data

Reference architecture baseline for GCP data platforms (Apache Beam, BigQuery, Cloud Functions, Pub/Sub). Hybrid warehouse/lakehouse with batch + streaming, Medallion layering. Consumed by private runtime repos.

apache-beam batch-processing bigquery cloud-functions cloud-storage data-engineering data-platform dataform gcp google-cloud-dataflow iceberg lakehouse medallion-architecture opentelemetry pubsub python reference-architecture slsa streaming supply-chain-security

Last synced: 21 May 2026

https://github.com/landerox/cloud-landerox-infra

GCP Terraform baseline and reference architecture — multi-environment CI/CD, defense-in-depth (validations + Conftest + Sigstore plan attestation), Workload Identity Federation, BigQuery medallion, recipes per module. OpenSSF Best Practices silver.

artifact-registry bigquery checkov cicd cloud-run cloud-scheduler conftest devsecops gcp iam infrastructure-as-code openssf reference-architecture secret-manager sigstore slsa terraform terraform-modules workload-identity-federation

Last synced: 21 May 2026

https://github.com/victoralfred/devsec

MLSecOps security pipeline tool - automated scanning, policy enforcement, compliance mapping, and ML validation for CI/CD

cli compliance devsec golang iso27001 mlsecops opa policy-as-code sast sbom secrets-detection security slsa soc2 supply-chain-security vulnerability-scanner

Last synced: 12 Mar 2026

https://github.com/kubedoll-heavy-industries/agentcontainers

Immutable, reproducible, least-privilege runtime environments for AI agents

ai-agents containers devcontainers ebpf oci security slsa

Last synced: 18 Apr 2026

https://github.com/laugiov/security-by-design

Security by Design reference: JWT/mTLS auth, RBAC, DevSecOps pipeline (SAST/DAST/SBOM/Cosign), Kubernetes hardening. Production-grade patterns.

api-security cosign devsecops fastapi gitlab-ci helm jwt-authentication kubernetes microservices mtls owasp platform-security python rbac sast-dast sbom security-by-design slsa supply-chain-security threat-modeling

Last synced: 01 May 2026

https://github.com/forgesworn/anvil

anvil: forge-hardened npm publishing for JS/TS libraries. Reproducible builds, OIDC trusted publishing, hard pre-publish gates. Pure bash, zero dependencies.

github-actions npm npm-publish oidc provenance release reproducible-builds slsa supply-chain-security trusted-publishing

Last synced: 18 Apr 2026

https://github.com/nais/salsa-action

Sign and attest images

slsa supply supply-chain-management

Last synced: 19 Mar 2026

https://github.com/pulseengine/sigil

Sigil — Supply chain security for WebAssembly. Embedded signatures, Sigstore keyless signing, SLSA provenance. Part of the PulseEngine toolchain.

pulseengine rust sigstore slsa supply-chain-security webassembly

Last synced: 01 Apr 2026

https://github.com/sebastienrousseau/inclusio

Accessibility-first publishing engine — PDF/UA-2 + WTPDF + PDF/A-4f, C2PA + PAdES + SLSA provenance, multi-format emission, MCP server.

accessibility c2pa eaa epub jats latex lualatex mcp model-context-protocol pades pdf-a pdf-ua pdf-ua-2 provenance publishing slsa tagged-pdf tagpdf wcag wtpdf

Last synced: 10 Jul 2026

https://github.com/automatanexus/nexusedge_talos_daemon

NexusEdge Talos Daemon — I2C hardware + 44 HVAC control algorithms for Raspberry Pi controllers. SLSA L3 attested releases.

building-automation control-systems edge-computing hailo hvac i2c industrial-iot iot nexusedge pid-controller raspberry-pi rust sequent-microsystems slsa smart-building

Last synced: 11 Jun 2026

https://github.com/shenxianpeng/slsa-provenance-demo

SLSA generate and verify provenance demo

slsa slsa-generic-generator slsa-provenance slsa3

Last synced: 10 Aug 2025

https://github.com/klein-business/legal-text-mcp-de

MCP server, HTTP API & CLI for German federal/state legal texts (BGB, DSGVO, …) with canonical IDs and cite-grade source provenance.

citation-resolver claude-desktop cli command-line-interface dsgvo eur-lex fastapi gdpr german-law gesetze gesetze-im-internet legal-tech legal-texts mcp mcp-server model-context-protocol python search slsa typer

Last synced: 30 Jun 2026

https://github.com/srujantata/supply-chain-security-pipeline

Software supply chain security: Syft SBOM, Cosign keyless signing via Sigstore, SLSA Level 2 provenance, Grype CVE gating, GitHub Actions pipeline

cosign devsecops grype sbom sigstore slsa supply-chain-security syft

Last synced: 28 Jun 2026

https://github.com/cmangun/agentic-artifacts

Artifact manifests and provenance rules for integrity-preserved agent outputs

agentic-systems data-integrity data-lineage manifest provenance slsa verifiable-ai

Last synced: 03 May 2026

https://github.com/trivoallan/houba

The single front door for external container images: harden, stamp, and trace every image you run.

cli container-images containers devsecops golden-images harbor image-hardening oci provenance python slsa supply-chain-security

Last synced: 11 Jun 2026

https://github.com/aslafy-z/coreruleset-plugins-image

OWASP CRS plugins as a minimal, signed OCI image for Coraza/Envoy WAFs.

coraza coreruleset cosign envoy image-volume kubernetes modsecurity oci-image owasp-crs security slsa waf

Last synced: 18 Jun 2026

https://github.com/aflock-ai/supply-chain-attacks

Catalog of real-world software supply-chain attacks reproduced as safe harnesses, each with cilock detection demonstrated by live CI. Trivy tag-rewrite, LiteLLM .pth stealer, Nx VS Code, actions-cool hijack, Shai-Hulud npm worm, Microsoft durabletask PyPI, GitHub source disclosure.

actions-cool attack-detection attestation cve-reproduction devsecops durabletask in-toto nx-attack opa-policy secretscan shai-hulud sigstore slsa supply-chain-attack supply-chain-security

Last synced: 22 Jun 2026

https://github.com/ifimust/srsr

Really Simple Service Registry

gin go golang microservices slsa

Last synced: 26 Feb 2026

https://github.com/aenguerrand/npm-publish-slsa-two-steps

Lab repository demonstrates how to create provenance without using the npm CLI and publish a package to npmjs.com with an attached provenance file (not generated by the npm CLI)

npmjs slsa supply-chain-security

Last synced: 20 Aug 2025