Stars
GUAC aggregates software security metadata into a high fidelity graph database.
🤖 The free, Open Source alternative to OpenAI, Claude and others. Self-hosted and local-first. Drop-in replacement, running on consumer-grade hardware. No GPU required. Runs gguf, transformers, dif…
A CLI tool for creating secure by design/default source repos.
The Go Cloud Development Kit (Go CDK): A library and tools for open cloud development in Go.
Github Action for ingesting SBOMs and Attestations into GUAC
🥑 Inspect and understand an organization's software supply chain using AI to enable stakeholders to make actionable decisions about software supply chain security
in-toto is a framework to protect supply chain integrity.
Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks
A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.
Docker and OCI Registry Client in Go and tooling using those libraries.
Better Prometheus alerts for Kubernetes - smart grouping, AI enrichment, and automatic remediation
The world’s fastest framework for building websites.