Skip to content
#

slsa

Here are 282 public repositories matching this topic...

Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks, detect malicious Python packages, or check conformance to frameworks, such as SLSA. Documentation:

  • Updated Sep 18, 2026
  • Python

Is your lockfile pwned? 5-second scan of npm/PyPI/Maven/Cargo/Go/RubyGems lockfiles for compromised packages — OSV + curated campaign feed, --min-age cooling-off gate, exit 4 when a scan is incomplete. SLSA L3, Sigstore-signed feed.

  • Updated Sep 20, 2026
  • Python

A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.

  • Updated Jan 28, 2024

Open authorization and accountability infrastructure for physical AI: short-lived capabilities, local action gates, replay protection, signed receipts, post-quantum ML-DSA-65, fleet policy/revocation distribution, and a zero-dependency offline browser verifier.

  • Updated Sep 21, 2026
  • Python

Git-native AI code provenance: records which AI agent wrote which line, signs each attribution with ed25519, stores it in your git history. Cross-agent (Claude Code, Cursor, Copilot, Codex, Windsurf, OpenCode, Gemini).

  • Updated Jun 8, 2026
  • Rust

Add this topic to your repo

To associate your repository with the slsa topic, visit your repo's landing page and select "manage topics."

Learn more