Skip to content
View puerco's full-sized avatar
🐽
Porkin' the code !
🐽
Porkin' the code !

Block or report puerco

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Securing open-source package ecosystems by originating, validating, and augmenting build attestations.

Go 642 33 Updated Sep 13, 2025

A proof-of-concept for how the SLSA Source Track could be implemented.

Go 8 11 Updated Sep 12, 2025

Security findings remediation tooling

Go 8 4 Updated Jul 16, 2025

Source code for Mozilla.ai's Lumigator platform

Python 256 23 Updated Sep 13, 2025

PURL to CPE Relationship mapping project.

Python 94 22 Updated Sep 13, 2025

simple terminal UI for git commands

Go 64,755 2,236 Updated Sep 7, 2025

Format agnostic SBOM tooling

Go 115 19 Updated Sep 10, 2025

RPM DB bindings for go

Go 68 61 Updated May 19, 2025

A set of reusable GitHub actions based on the Kubernetes Release Engineering Tooling

13 7 Updated Sep 4, 2025

A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.

Go 65 9 Updated Sep 11, 2025

Fast linters runner for Go

Go 17,638 1,493 Updated Sep 12, 2025

Java library for generating, consuming, and operating on OpenVEX documents

Java 2 Updated Mar 25, 2024

A tool to create, transform and attest VEX metadata

Go 154 22 Updated Sep 9, 2025

An SBOM query language and associated utilities

Go 54 3 Updated Jan 22, 2024

Dynamic GitHub Actions from Wolfi packages

44 4 Updated May 15, 2025

OpenVEX Specification

158 20 Updated Jun 3, 2025

Go module to generate and transform VEX documents

Go 48 17 Updated Sep 11, 2025
Go 4 Updated Aug 8, 2022

A tool that takes two or more micro SBOMs and composes them into one distributable SBOM

Go 23 4 Updated Mar 23, 2023

GUAC aggregates software security metadata into a high fidelity graph database.

Go 1,407 184 Updated Sep 8, 2025

Code-signing for npm packages

TypeScript 167 30 Updated Aug 26, 2025

A curated list of awesome actions to use on GitHub

26,723 1,556 Updated Sep 1, 2024
JavaScript 101 21 Updated Sep 27, 2024

Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, produce and use.

189 35 Updated Feb 16, 2024

Keyless Git signing using Sigstore

Go 1,021 70 Updated Sep 12, 2025

Build OCI images from APK packages directly without Dockerfile

Go 1,422 179 Updated Sep 13, 2025

Interfaces and implementations for building Kubernetes releases.

Go 17 31 Updated Sep 9, 2025

Container image registry that serves images built fresh when you ask for them

Go 231 13 Updated Feb 14, 2025

Kubermatic KubeOne automate cluster operations on all your cloud, on-prem, edge, and IoT environments.

Go 1,463 250 Updated Sep 9, 2025
Next