A framework to protect software supply chain integrity
in-toto is a framework to protect supply chain integrity.
in-toto is a framework to secure the software supply chain.
Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.
in-toto Attestation Framework
in-toto Enhancements
Specification and other related documents.
Securing Alice's, Bob's and Carl's software supply chain using in-toto
in-toto/demo’s past year of commit activity Python 93 42 3 2 Updated Jul 3, 2025Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for software artifacts.
in-toto/archivista’s past year of commit activityThe in-toto website and documentation
in-toto/in-toto.io’s past year of commit activity SCSS 7 21 16 1 Updated Jun 30, 2025Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
in-toto/witness’s past year of commit activityFriends of in-toto! A place to record integrations and adoptions of the in-toto specification.
in-toto/friends’s past year of commit activitySoftware Supply Chain Attribute Integrity (SCAI) Demos and CLI tools
in-toto/scai-demos’s past year of commit activity Go 18 Apache-2.0 4 1 1 Updated Jun 27, 2025A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.
in-toto/in-toto-golang’s past year of commit activityPrototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts
in-toto/attestation-verifier’s past year of commit activity Go 16 6 4 5 Updated Jun 16, 2025You can’t perform that action at this time.
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4