/macaron-utilities

Macaron Untilities is a collection of companion tools and plugins for the Macaron supply chain security framework.

Primary LanguageJavaUniversal Permissive License v1.0UPL-1.0

semver conventional-commits

Macaron Utilities

Macaron Utilities is a collection of companion tools and plugins for the Macaron supply chain security framework.

This repository includes:

  • Maven and Gradle plugins to verify software artifacts using Verification Summary Attestations (VSAs) generated by Macaron.
    • Consisting of a common library in artifact-verifier, and the plugins in artifact-verifier-maven and artifact-verifier-gradle.

Installation

Build and install artifact-verifier first, then build and install artifact-verifier-maven and artifact-verifier-gradle afterward.

Contributing

This project welcomes contributions from the community. Before submitting a pull request, please review our contribution guide

Security

Please consult the security guide for our responsible security vulnerability disclosure process

License

Copyright (c) 2025, 2025 Oracle and/or its affiliates. Macaron utilities are licensed under the Universal Permissive License (UPL), Version 1.0.