Projects with this topic
-
Go + React 的 B2B2C 多商家电商实践:10 个 ConnectRPC 微服务、control-tower 网关/配置控制面、pnpm monorepo 前端(consumer/merchant/admin/Tauri),Cilium Gateway API + ArgoCD 交付,Cosign/SBOM/Trivy 供应链门禁。发布构建在 GitHub 镜像仓(lens077/ecommerce),这里跑每次 push 的门禁。
Updated -
Toolchain image for the Coroboros security gates.
UpdatedUpdated -
Standalone artefact signing and verification CLI for the phpboyscout ecosystem · https://sigillum.phpboyscout.uk
Updated -
OpenPGP/WKD release signing & verification — a light, dependency-inverted Go library (sign via crypto.Signer backends, verify via embedded+WKD trust). Reusable without the go-tool-base framework. · https://signing.phpboyscout.uk
Updated -
AWS KMS signing backend for gitlab.com/phpboyscout/signing — implements the Backend contract (crypto.Signer over a KMS RSA key). Blank-import to activate; reusable without the go-tool-base framework. · https://signing.phpboyscout.uk
Updated -
AWS KMS provider for go/encryption — DeriveSharedSecret and Sign backends for KMS-held OpenPGP certification and ECDH encryption keys, so no private key material ever leaves KMS.
Updated -
Shareable sign & keys Cobra command builders for the phpboyscout signing toolchain
Updated -
OpenPGP certificate assembly & ECDH message decryption — a dependency-inverted Go library. Assemble a certificate whose private halves live in an external KMS, and decrypt messages addressed to it from a raw ECDH shared secret. · https://encryption.go.phpboyscout.uk
Updated -
Read-only mirror of cicd-sensor: An open-source runtime security monitoring tool for CI/CD environments leveraging eBPF.
Updated -
Integrity monitoring for the files your AI coding agent obeys — detects drift, invisible characters, bidi controls, and homoglyphs in CLAUDE.md, .cursorrules, settings.json and friends.
Updated -
-
A fast, minimal viewer for SPDX SBOMs: cascading documents, compliance profiles (NTIA, BSI TR-03183), VEX overlay. Client-side, files never leave your machine.
Updated -
Structural integrity gate. Intercepts changes before execution and rejects when historical invariants break — even when cosign says Verified OK.
Updated -
A fast, minimal viewer for Open Component Model deliveries: CTF archives, embedded SBOMs, client-side signature verification, OCI registry browsing.
Updated -
-
A comprehensive guide to software supply chain security. This open-source manuscript provides security professionals and developers with practical strategies to defend against ecosystem threats.
Updated -
Kubernetes-native Helm auditor for supply chain security, aggregating SBOM, vulnerability, and provenance data.
Updated