GUAC aggregates software security metadata into a high fidelity graph database.
-
Updated
Apr 16, 2025 - Go
GUAC aggregates software security metadata into a high fidelity graph database.
Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.
Enabling Software Supply Chain Security Capabilities in ArgoCD
Github Action implementation of SLSA Provenance Generation
Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts
Library to create, verify, and evaluate policy for attestations on container images
Add a description, image, and links to the in-toto topic page so that developers can more easily learn about it.
To associate your repository with the in-toto topic, visit your repo's landing page and select "manage topics."