Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
-
Updated
Jun 16, 2025 - Go
8000
Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
SSH Certificate Authority with device attestation
vexctl is a tool to attest VEX impact statements
An OIDC authorization server building blocks with security and privacy by design philosophy.
An experimental (but fully functional) Remote Attestation Engine and Applications for TPM2.0 based systems (cloud, edge, IoT etc)
Verify and assert policy on YubiKey attestation certificates
Platform software for Trusted Computing - TPM 2.0, Certificate Authority, and Web Services required to perform Local and Remote Attestation, provision, deploy, manage, and secure connected devices and networks at scale.
Library to create, verify, and evaluate policy for attestations on container images
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Easy non-interactive initialization of a YubiKey's OpenPGP mode using sane settings and Ed25519/Curve25519 keys, ready for SSH use and attestation.
Sign and package attestations in sigstore bundles
Jane Attestation Server
Gofeas is a working Go client for Grafeas
Add a description, image, and links to the attestation topic page so that developers can more easily learn about it.
To associate your repository with the attestation topic, visit your repo's landing page and select "manage topics."