This repository contains free tools to generate and verify SLSA Build Level 3 provenance for native GitHub projects using GitHub Actions. Developers can build their software using a secure process that protects against many supply chain attacks and tampering. Users of their software can verify a tamper-proof statement of the process to know how the software was created.
Features
- Provenance is information, or metadata, about how a software artifact was created
- Documentation available
- Examples available
- Generate provenance
- Easy to use
- Verify provenance
- Build Your Own Builder
Categories
SecurityLicense
Apache License V2.0Follow SLSA GitHub Generator
Other Useful Business Software
Stop Storing Third-Party Tokens in Your Database
Rolling your own OAuth token storage can be a security liability. Token Vault securely stores access and refresh tokens from federated providers and handles exchange and renewal automatically. Connected accounts, refresh exchange, and privileged worker flows included.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of SLSA GitHub Generator!