Capability-based sandboxes with fine-grained policies The next-generation isolation primitive โ brokering access directly within the agent's operating context, with zero setup and zero latency
-
Updated
May 8, 2026 - Rust
Capability-based sandboxes with fine-grained policies The next-generation isolation primitive โ brokering access directly within the agent's operating context, with zero setup and zero latency
MDA Open Spec โ a Markdown superset for agent-facing documents. One .mda source compiles to drop-in SKILL.md, AGENTS.md, MCP-SERVER.md, and CLAUDE.md. JSON Schema validated, with typed dependency graph, footnote relationships, and Sigstore-anchored signatures. For agentskills.io and AAIF runtimes.
An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster
Supply chain security for ML
Trusted builds made easy! A cloud-native software factory for building, testing, and releasing trusted software artifacts
Enabling Software Supply Chain Security Capabilities in ArgoCD
The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data Poisoning, PII, and Prompt Injections. Secure your AI Supply Chain.
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
PDF signing utility supporting GPG and Sigstore (Google, GitHub, Microsoft accounts / keyless OIDC) signatures, multi-party signing, making it easy to sign and verify documents without heavyweight PDF signing stacks, making your PDFs authentic, tamper-proof, fully compatible with regular readers; all while costing zero-dollars to use.
Verify PyPI package attestations and improve Python supply-chain security
Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations
๐ด๐ก๐ข The Amazing Multipurpose Policy Engine (and L)
๐ Rekor transparency log monitoring and alerting
Add a description, image, and links to the sigstore topic page so that developers can more easily learn about it.
To associate your repository with the sigstore topic, visit your repo's landing page and select "manage topics."