13 repos
Tools and infrastructure for securing the software supply chain, from code provenance and artifact signing to dependency analysis and security scoring. The cluster centers on establishing trust and transparency in open-source software through mechanisms like code signing (Sigstore), artifact transparency logs (Rekor), and automated security assessments (OpenSSF Scorecard). Most repos are written in Go with supporting JavaScript and Python tooling, spanning both CLI utilities and web-based frontends for auditing and validating software artifacts.