attestation

There are 147 repositories under attestation topic.

  • GrapheneOS/Auditor

    Hardware-based attestation / intrusion detection app for Android devices. It provides both local verification with another Android device via QR codes and optional scheduled server-based verification with support for alert emails. It uses hardware-backed keys and attestation support as the foundation and chains trust to the app for software checks.

    Language:Java5723011690
  • in-toto/witness

    Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.

    Language:Go4972517970
  • chainloop-dev/chainloop

    Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more

    Language:Go4901062738
  • keylime

    keylime/keylime

    A CNCF Project to Bootstrap & Maintain Trust on the Edge / Cloud and IoT

    Language:Python48123515168
  • intel/confidential-computing-zoo

    Confidential Computing Zoo provides confidential computing solutions based on Intel SGX, TDX, HEXL, etc. technologies.

    Language:C++333111464
  • bureado/awesome-software-supply-chain-security

    A compilation of resources in the software supply chain security domain, with emphasis on open source

  • in-toto/attestation

    in-toto Attestation Framework

    Language:Rust2982314790
  • ShaneK2/inVtero.net

    inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques

    Language:C#28729351
  • Consensys/linea-attestation-registry

    Verax is a shared registry for storing attestations of public interest on EVM chains, designed to enhance data discoverability and consumption for dApps across the network.

    Language:TypeScript1591348395
  • signum

    a-sit-plus/signum

    Kotlin Multiplatform Crypto/PKI/ASN.1 Library with Attestation and Hardware-Backed Crypto Support on Mobile

    Language:Kotlin142511912
  • GrapheneOS/AttestationServer

    attestation.app remote attestation server. Server code for use with the Auditor app: https://github.com/GrapheneOS/Auditor. It provides two services: submission of attestation data samples and a remote attestation implementation with email alerts to go along with the local implementation based on QR code scanning in the app.

    Language:Java133127149
  • coinbase/verifications

    📜 "Coinbase Verifications" is a set of Coinbase-verified onchain attestations that enable access to apps and other onchain benefits.

    Language:Solidity1148330
  • confidential-containers/trustee

    Attestation and Secret Delivery Components

    Language:Rust10721234127
  • mchmarny/s3cme

    Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance

    Language:Go1046711
  • cyclonedx-python-lib

    CycloneDX/cyclonedx-python-lib

    Python implementation of OWASP CycloneDX

    Language:Python871220853
  • hex-five/multizone-sdk

    MultiZone® Security TEE is the quick and safe way to add security and separation to any RISC-V processors. The RISC-V standard ISA doesn't define TrustZone-like primitives to provide hardware separation. To shield critical functionality from untrusted third-party components, MultiZone provides hardware-enforced, software-defined separation of multi

    Language:C86104925
  • veehaitch/devicecheck-appattest

    Server-side library to validate the authenticity of Apple App Attest artifacts, written in Kotlin.

    Language:Kotlin748129
  • ARM-software/psa-api

    Documentation source and development of the PSA Certified API

    Language:C691511931
  • virtee/sev-snp-measure

    Calculate AMD SEV/SEV-ES/SEV-SNP measurement for confidential computing

    Language:Python6962218
  • kubernetes-sigs/tejolote

    A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.

    Language:Go65549
  • Foxboron/ssh-tpm-ca-authority

    SSH Certificate Authority with device attestation

    Language:Go55322
  • Catherine22/SecuritySample

    (Android) Hide encrypted secret API keys in C/C++ code, retrieve and decrypt them via JNI. Google SafetyNet APIs example.

    Language:Java54326
  • Azure/blockchain-supply-chain-solution

    Umbrella repository for blockchain based supply-chain services and clients

    Language:Shell5228034
  • chainguard-dev/vex

    vexctl is a tool to attest VEX impact statements

    Language:Go4531812
  • pkic/remote-key-attestation

    Remote Key Attestation

  • GrapheneOS-Archive/AttestationSamples

    A small subset of the submitted sample data from https://github.com/GrapheneOS/Auditor. It has a sample attestation certificate chain per device model (ro.product.model) along with a subset of the system properties from the sample as supplementary information.

    Language:Shell357223
  • nokia/AttestationEngine

    An experimental (but fully functional) Remote Attestation Engine and Applications for TPM2.0 based systems (cloud, edge, IoT etc)

    Language:Go2782416
  • zntrio/solid

    An OIDC authorization server building blocks with security and privacy by design philosophy.

    Language:Go27205
  • adrianlshaw/LightVerifier

    Simple and scalable Linux tools for verifying TPM-based remote attestations 🔬⚖️🔐⛓📏📜

    Language:Shell22423
  • hex-five/multizone-iot-sdk

    MultiZone® Trusted Firmware is the quick and safe way to build secure IoT applications with any RISC-V processor. It provides secure access to commercial and private IoT clouds, real-time monitoring, secure boot, and remote firmware updates. The built-in Trusted Execution Environment provides hardware-enforced separation ...

    Language:C20041
  • joemiller/yk-attest-verify

    Verify and assert policy on YubiKey attestation certificates

    Language:Go20332
  • zero-savvy/zk-remote-attestation

    Implementation of zRA protocol, a non-interactive method for constructing a transparent remote attestation (RA) protocol based on zkSNARKs.

    Language:Circom19001
  • hex-five/multizone-linux

    MultiZone® Security Enclave for Linux

    Language:C1810512
  • kinvolk/azure-cvm-tooling

    Libraries and tools for Confidential Computing on Azure

    Language:Rust18112016
  • jedda/step-posture-connector

    A middleware tool to assist step-ca with posture info during an ACME device-attest-01 challenge.

    Language:Go17201
  • jeremyhahn/go-trusted-platform

    Platform software for Trusted Computing - TPM 2.0, Certificate Authority, and Web Services required to perform Local and Remote Attestation, provision, deploy, manage, and secure connected devices and networks at scale.

    Language:Go16211