/guac

Primary LanguageGoApache License 2.0Apache-2.0

GUAC: Graph for Understanding Artifact Composition

image

The GUAC: Graph for Understanding Artifact Composition project aims to create a means to ingest, validate and parse artifact information (i.e. in-toto attestations, SBOM, etc.) from various data sources and represent and store them in a knowledge graph, where users can query information about artifacts or request evidence of certain properties of an artifact. The purpose of this aims to satisfy the use case of being a monitor for public supply chain and security documents as well as for internal use by organizations to query information about artifacts that they use.

A few examples of questions answered by GUAC include:

image

Architecture

Here is an overview of the architecture of GUAC:

image

Additional References

Communication

All communication should be done through issues, unless it is a private matter. In that case, an e-mail should be sent to guac-maintainers@googlegroups.com.

Governance

Information about governance can be found here.