This repository contains free tools to generate and verify SLSA Build Level 3 provenance for native GitHub projects using GitHub Actions. Developers can build their software using a secure process that protects against many supply chain attacks and tampering. Users of their software can verify a tamper-proof statement of the process to know how the software was created.
Features
- Provenance is information, or metadata, about how a software artifact was created
- Documentation available
- Examples available
- Generate provenance
- Easy to use
- Verify provenance
- Build Your Own Builder
Categories
SecurityLicense
Apache License V2.0Follow SLSA GitHub Generator
Other Useful Business Software
Outgrown Windows Task Scheduler?
Windows Task Scheduler wasn't built for complex, cross-platform automation. Get a free diagnostic that shows exactly where things are failing and provides remediation recommendations. Interactive HTML report delivered in minutes.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of SLSA GitHub Generator!