awesome-repositories.com
Blog
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektÜber unsRanking-MethodikPresseMCP-Server
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to slsa-framework/slsa

Open-source alternatives to Slsa

14 open-source projects similar to slsa-framework/slsa, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Slsa alternative.

  • anchore/syftAvatar von anchore

    anchore/syft

    8,399Auf GitHub ansehen↗

    Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche

    Gocontainerscyclonedxdocker
    Auf GitHub ansehen↗8,399
  • aquasecurity/chain-benchAvatar von aquasecurity

    aquasecurity/chain-bench

    774Auf GitHub ansehen↗

    An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

    Go
    Auf GitHub ansehen↗774
  • deislabs/ratifyAvatar von deislabs

    deislabs/ratify

    303Auf GitHub ansehen↗

    Artifact Ratification Framework (CNCF Sandbox)

    Go
    Auf GitHub ansehen↗303
  • denysvuika/supply-chain-inspectorAvatar von DenysVuika

    DenysVuika/supply-chain-inspector

    3Auf GitHub ansehen↗

    A standalone, zero-dependency Node.js script for supply chain security analysis of npm dependencies.

    JavaScript
    Auf GitHub ansehen↗3
  • en/code-securityE

    en/code-security

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Find more with AI search
  • grafeas/kritisAvatar von grafeas

    grafeas/kritis

    710Auf GitHub ansehen↗

    Deploy-time Policy Enforcer for Kubernetes applications

    Go
    Auf GitHub ansehen↗710
  • in-toto/attestationAvatar von in-toto

    in-toto/attestation

    341Auf GitHub ansehen↗

    in-toto Attestation Framework

    Rust
    Auf GitHub ansehen↗341
  • os-scar/overlayAvatar von os-scar

    os-scar/overlay

    228Auf GitHub ansehen↗

    Overlay

    JavaScript
    Auf GitHub ansehen↗228
  • sigstore/cosignAvatar von sigstore

    sigstore/cosign

    5,667Auf GitHub ansehen↗

    Cosign is a tool for signing and verifying software artifacts, primarily those stored in OCI-compatible registries such as container images, Helm charts, SBOMs, and Tekton bundles. It supports keyless signing using ephemeral keys and short-lived certificates from the Sigstore public-good infrastructure, associating signatures with an OpenID Connect identity rather than a long-lived cryptographic key. The project provides multiple signing and verification methods, including private keys, key pairs stored in KMS providers like AWS KMS and Azure Key Vault, and hardware security keys. It can sign

    Go
    Auf GitHub ansehen↗5,667
  • sigstore/fulcioAvatar von sigstore

    sigstore/fulcio

    859Auf GitHub ansehen↗

    Sigstore OIDC PKI

    Go
    Auf GitHub ansehen↗859
  • sigstore/rekorAvatar von sigstore

    sigstore/rekor

    1,168Auf GitHub ansehen↗

    Software Supply Chain Transparency Log

    Go
    Auf GitHub ansehen↗1,168
  • spectralops/preflightAvatar von spectralops

    spectralops/preflight

    157Auf GitHub ansehen↗

    preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.

    Go
    Auf GitHub ansehen↗157
  • step-security/harden-runnerAvatar von step-security

    step-security/harden-runner

    1,206Auf GitHub ansehen↗

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

    TypeScript
    Auf GitHub ansehen↗1,206
  • tektoncd/chainsAvatar von tektoncd

    tektoncd/chains

    271Auf GitHub ansehen↗

    Supply Chain Security in Tekton Pipelines

    Go
    Auf GitHub ansehen↗271