← back

category

Software supply chain

Sign and verify artifacts, and assess the security practices of the projects you depend on.

Side by side

Software supply chain
ToolStarsLicenceTermsSelf-hostedLanguageLatestLast push
Cosign6.3kApache-2.0Open sourceNoGov3.1.32026-10-05
OpenSSF Scorecard5.7kApache-2.0Open sourceNoGov5.5.02026-10-06
Notation498Apache-2.0Open sourceNoGov1.3.22026-09-25

3 tools

Cosign

Code signing and transparency for containers and binaries

Language
Go
Licence
Apache-2.0
Stars
6.3k
Latest
v3.1.3
Last push
2026-10-05