-
09:53
(UTC -06:00) - @puerco
- in/puerco
- @puerco.mx
Stars
Securing open-source package ecosystems by originating, validating, and augmenting build attestations.
A proof-of-concept for how the SLSA Source Track could be implemented.
Source code for Mozilla.ai's Lumigator platform
A set of reusable GitHub actions based on the Kubernetes Release Engineering Tooling
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Java library for generating, consuming, and operating on OpenVEX documents
An SBOM query language and associated utilities
A tool that takes two or more micro SBOMs and composes them into one distributable SBOM
GUAC aggregates software security metadata into a high fidelity graph database.
A curated list of awesome actions to use on GitHub
Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, produce and use.
Build OCI images from APK packages directly without Dockerfile
Interfaces and implementations for building Kubernetes releases.
Container image registry that serves images built fresh when you ask for them
Kubermatic KubeOne automate cluster operations on all your cloud, on-prem, edge, and IoT environments.