← voltar

categoria

Software supply chain

Sign and verify artifacts, and assess the security practices of the projects you depend on.

Lado a lado

Software supply chain
FerramentaEstrelasLicençaTermosAuto-hospedadoLinguagemÚltima releaseÚltimo push
Cosign6.3kApache-2.0Código abertoNãoGov3.1.32026-10-05
OpenSSF Scorecard5.7kApache-2.0Código abertoNãoGov5.5.02026-10-06
Notation498Apache-2.0Código abertoNãoGov1.3.22026-09-25

3 ferramentas

Cosign

Code signing and transparency for containers and binaries

Linguagem
Go
Licença
Apache-2.0
Estrelas
6.3k
Última release
v3.1.3
Último push
2026-10-05
Notation

A CLI tool to sign and verify artifacts

Linguagem
Go
Licença
Apache-2.0
Estrelas
498
Última release
v1.3.2
Último push
2026-09-25