For more about this fork, including all Features & Contributors, see the Wiki tab.
-
Updated
Sep 16, 2026 - Java
For more about this fork, including all Features & Contributors, see the Wiki tab.
Deterministic software attestation for AI-augmented development — witness, probe, and seal any repo with SHA-256. Fleet registry across 131 VERITAS nodes. Agent-native, zero cloud.
Public Tracking Repository for DEPs (DBoM Enhancement Proposals)
Jenkins plugin for Xygeni - End to end software development and delivery security
Zero-trust software supply-chain attestation platform. Ed25519-signed builds are chained via SHA-256, cross-verified by a 5-node PoA quorum, and scored by an Isolation Forest model to catch stolen-key misuse and tampering before install.
Reference workflows, scripts, and templates for hardening CI/CD pipelines with Sigstore, SLSA, and SBOMs.
To associate your repository with the software-attestation topic, visit your repo's landing page and select "manage topics."