Open source · Compliance

DSI SLSA Provenance Apache-2.0

Emits SLSA v1.0 provenance for every build, signed with Sigstore, so a released artifact can be traced to its source commit.

Browse the catalogue

Public repository

https://github.com/dev-sec-it/slsa-provenance

View repository

Releases, issues and the commit history are on the repository, so the license and the maintenance status can be checked against the last tagged release rather than taken on trust.

Catalogue record

The facts a buyer screens on first

Every value below is copied from the catalogue entry and is verifiable against the public repository.

License
Apache-2.0

OSI identifier, as published in the repository.

Stack
Go

Primary language and runtime.

Status
Beta

As recorded in the DEV SEC IT catalogue.

Stars
430

Counted from the public repository at the time of writing.

What we maintain

Our contribution to DSI SLSA Provenance

This project is on the catalogue because we own part of it. The parts we wrote, review and release are named here; everything else is upstream work we depend on.

Maintenance

Maintained by DEV SEC IT

What we wrote

Sigstore signing and the provenance attestor

First tagged release

First tagged release in 2025.

Talk to us

Need this running inside your own perimeter?

We maintain this project and the platforms built on it. If you want a deployment, a review or a fix against your environment, the same engineers who ship it can scope it.

All open source