GUAC aggregates software security metadata into a high fidelity graph database.
-
Updated
Sep 22, 2026 - Go
GUAC aggregates software security metadata into a high fidelity graph database.
Language-agnostic SLSA provenance generation for Github Actions
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Developer-centric tool to secure your software supply chain.
Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks, detect malicious Python packages, or check conformance to frameworks, such as SLSA. Documentation:
Trusted builds made easy! A cloud-native software factory for building, testing, and releasing trusted software artifacts
Is your lockfile pwned? 5-second scan of npm/PyPI/Maven/Cargo/Go/RubyGems lockfiles for compromised packages — OSV + curated campaign feed, --min-age cooling-off gate, exit 4 when a scan is incomplete. SLSA L3, Sigstore-signed feed.
A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.
Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance
Open authorization and accountability infrastructure for physical AI: short-lived capabilities, local action gates, replay protection, signed receipts, post-quantum ML-DSA-65, fleet policy/revocation distribution, and a zero-dependency offline browser verifier.
Official Docker-maintained reusable GitHub Actions workflows to securely build container images
Cross-platform developer workstation control plane powered by chezmoi — adaptive terminal themes, AI CLI workflows, read-only MCP, WASM attestations, encrypted secrets, and SLSA-verified releases.
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations
Github Action implementation of SLSA Provenance Generation
GitHub Action to generate an attestation for the build provenance of a plugin zip file on wordpress.org
Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.
Git-native AI code provenance: records which AI agent wrote which line, signs each attribution with ed25519, stores it in your git history. Cross-agent (Claude Code, Cursor, Copilot, Codex, Windsurf, OpenCode, Gemini).
FIPS 203 ML-KEM (CRYSTALS-Kyber) for Rust. Pure-Rust, no_std, ACVP 180/180, KyberSlash-clean, SLSA L3 + cosign-signed releases. Published on crates.io as kyberlib and kyberlib-wasm.
All-in-one Python template. One click. Everything included.
To associate your repository with the slsa topic, visit your repo's landing page and select "manage topics."