← retour

catégorie

Software supply chain

Sign and verify artifacts, and assess the security practices of the projects you depend on.

Côte à côte

Software supply chain
OutilÉtoilesLicenceConditionsAuto-hébergeableLangageDernière releaseDernier push
Cosign6.3kApache-2.0Open sourceNonGov3.1.32026-10-05
OpenSSF Scorecard5.7kApache-2.0Open sourceNonGov5.5.02026-10-06
Notation498Apache-2.0Open sourceNonGov1.3.22026-09-25

3 outils

Cosign

Code signing and transparency for containers and binaries

Langage
Go
Licence
Apache-2.0
Étoiles
6.3k
Dernière release
v3.1.3
Dernier push
2026-10-05