← volver

categoría

Software supply chain

Sign and verify artifacts, and assess the security practices of the projects you depend on.

Comparativa

Software supply chain
HerramientaEstrellasLicenciaCondicionesAutoalojableLenguajeÚltima versiónÚltimo push
Cosign6.3kApache-2.0Código abiertoNoGov3.1.32026-10-05
OpenSSF Scorecard5.7kApache-2.0Código abiertoNoGov5.5.02026-10-06
Notation498Apache-2.0Código abiertoNoGov1.3.22026-09-25

3 herramientas

Cosign

Code signing and transparency for containers and binaries

Lenguaje
Go
Licencia
Apache-2.0
Estrellas
6.3k
Última versión
v3.1.3
Último push
2026-10-05
Notation

A CLI tool to sign and verify artifacts

Lenguaje
Go
Licencia
Apache-2.0
Estrellas
498
Última versión
v1.3.2
Último push
2026-09-25