awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
sigstore avatar

sigstore/rekor

0
View on GitHub↗
1,168 stars·214 forks·Go·Apache-2.0·7 viewssigstore.dev↗

Rekor

Software Supply Chain Transparency Log

Features

  • Supply Chain Security - Maintains a tamper-resistant ledger for software supply chain transparency.

Star history

Star history chart for sigstore/rekorStar history chart for sigstore/rekor

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Rekor

Similar open-source projects, ranked by how many features they share with Rekor.
  • aquasecurity/chain-benchaquasecurity avatar

    aquasecurity/chain-bench

    774View on GitHub↗

    An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

    Go
    View on GitHub↗774
  • deislabs/ratifydeislabs avatar

    deislabs/ratify

    303View on GitHub↗

    Artifact Ratification Framework (CNCF Sandbox)

    Go
    View on GitHub↗303
  • denysvuika/supply-chain-inspectorDenysVuika avatar

    DenysVuika/supply-chain-inspector

    3View on GitHub↗

    A standalone, zero-dependency Node.js script for supply chain security analysis of npm dependencies.

    JavaScript
    View on GitHub↗3
  • anchore/syftanchore avatar

    anchore/syft

    8,399View on GitHub↗

    Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche

    Gocontainerscyclonedxdocker
    View on GitHub↗8,399
See all 14 alternatives to Rekor→

Frequently asked questions

What does sigstore/rekor do?

Software Supply Chain Transparency Log

What are the main features of sigstore/rekor?

The main features of sigstore/rekor are: Supply Chain Security.

What are some open-source alternatives to sigstore/rekor?

Open-source alternatives to sigstore/rekor include: aquasecurity/chain-bench — An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software… deislabs/ratify — Artifact Ratification Framework (CNCF Sandbox). denysvuika/supply-chain-inspector — A standalone, zero-dependency Node.js script for supply chain security analysis of npm dependencies. en/code-security. grafeas/kritis — Deploy-time Policy Enforcer for Kubernetes applications. anchore/syft — Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes…