attestation

There are 122 repositories under attestation topic.

  • chiteroman/BootloaderSpoofer

    Spoof locked bootloader on local attestations

    Language:Java73519075
  • GrapheneOS/Auditor

    Hardware-based attestation / intrusion detection app for Android devices. It provides both local verification with another Android device via QR codes and optional scheduled server-based verification with support for alert emails. It uses hardware-backed keys and attestation support as the foundation and chains trust to the app for software checks.

    Language:Java4792910485
  • keylime

    keylime/keylime

    A CNCF Project to Bootstrap & Maintain Trust on the Edge / Cloud and IoT

    Language:Python41422478148
  • in-toto/witness

    Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.

    Language:Go4042516357
  • chainloop-dev/chainloop

    Chainloop is an Open Source evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, CSAF files, QA reports, and more.

    Language:Go3641041827
  • intel/confidential-computing-zoo

    Confidential Computing Zoo provides confidential computing solutions based on Intel SGX, TDX, HEXL, etc. technologies.

    Language:CMake301141059
  • ShaneK2/inVtero.net

    inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques

    Language:C#27830357
  • bureado/awesome-software-supply-chain-security

    A compilation of resources in the software supply chain security domain, with emphasis on open source

  • in-toto/attestation

    in-toto Attestation Framework

    Language:Go2302313259
  • Consensys/linea-attestation-registry

    Verax is a shared registry for storing attestations of public interest on EVM chains, designed to enhance data discoverability and consumption for dApps across the network.

    Language:TypeScript1221338464
  • GrapheneOS/AttestationServer

    attestation.app remote attestation server. Server code for use with the Auditor app: https://github.com/GrapheneOS/Auditor. It provides two services: submission of attestation data samples and a remote attestation implementation with email alerts to go along with the local implementation based on QR code scanning in the app.

    Language:Java105127045
  • coinbase/verifications

    📜 "Coinbase Verifications" is a set of Coinbase-verified onchain attestations that enable access to apps and other onchain benefits.

    Language:Solidity807111
  • hex-five/multizone-sdk

    MultiZone® Security TEE is the quick and safe way to add security and separation to any RISC-V processors. The RISC-V standard ISA doesn't define TrustZone-like primitives to provide hardware separation. To shield critical functionality from untrusted third-party components, MultiZone provides hardware-enforced, software-defined separation of multi

    Language:C80114924
  • cyclonedx-python-lib

    CycloneDX/cyclonedx-python-lib

    Python implementation of OWASP CycloneDX

    Language:Python671515638
  • veehaitch/devicecheck-appattest

    Server-side library to validate the authenticity of Apple App Attest artifacts, written in Kotlin.

    Language:Kotlin668118
  • confidential-containers/trustee

    Attestation and Secret Delivery Components

    Language:Rust592218781
  • ARM-software/psa-api

    Documentation source and development of the PSA Certified API

    Language:C55178626
  • kubernetes-sigs/tejolote

    A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.

    Language:Go55649
  • virtee/sev-snp-measure

    Calculate AMD SEV/SEV-ES/SEV-SNP measurement for confidential computing

    Language:Python5562015
  • Catherine22/SecuritySample

    (Android) Hide encrypted secret API keys in C/C++ code, retrieve and decrypt them via JNI. Google SafetyNet APIs example.

    Language:Java54426
  • Azure/blockchain-supply-chain-solution

    Umbrella repository for blockchain based supply-chain services and clients

    Language:Shell5229034
  • mchmarny/s3cme

    Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance

    Language:Go50579
  • signum

    a-sit-plus/signum

    Kotlin Multiplatform Crypto/PKI Library and ASN1 Parser + Encoder

    Language:Kotlin495413
  • chainguard-dev/vex

    vexctl is a tool to attest VEX impact statements

    Language:Go4431812
  • Foxboron/ssh-tpm-ca-authority

    SSH Certificate Authority with device attestation

    Language:Go44311
  • GrapheneOS-Archive/AttestationSamples

    A small subset of the submitted sample data from https://github.com/GrapheneOS/Auditor. It has a sample attestation certificate chain per device model (ro.product.model) along with a subset of the system properties from the sample as supplementary information.

    Language:Shell338223
  • pkic/remote-key-attestation

    Remote Key Attestation

  • zntrio/solid

    An OIDC authorization server building blocks with security and privacy by design philosophy.

    Language:Go26305
  • nokia/AttestationEngine

    An experimental (but fully functional) Remote Attestation Engine and Applications for TPM2.0 based systems (cloud, edge, IoT etc)

    Language:Go2382417
  • adrianlshaw/LightVerifier

    Simple and scalable Linux tools for verifying TPM-based remote attestations 🔬⚖️🔐⛓📏📜

    Language:Shell21523
  • hex-five/multizone-iot-sdk

    MultiZone® Trusted Firmware is the quick and safe way to build secure IoT applications with any RISC-V processor. It provides secure access to commercial and private IoT clouds, real-time monitoring, secure boot, and remote firmware updates. The built-in Trusted Execution Environment provides hardware-enforced separation ...

    Language:C19141
  • hex-five/multizone-linux

    MultiZone® Security Enclave for Linux

    Language:C1711512
  • joemiller/yk-attest-verify

    Verify and assert policy on YubiKey attestation certificates

    Language:Go17332
  • kinvolk/azure-cvm-tooling

    Libraries and tools for Confidential Computing on Azure

    Language:Rust1411189
  • rustymagnet3000/ios_devicecheck_app_attest

    Understand iOS 14's DeviceCheck and DCDevice classes.

    Language:Swift14203
  • zero-savvy/zk-remote-attestation

    Implementation of zRA protocol, a non-interactive method for constructing a transparent remote attestation (RA) protocol based on zkSNARKs.

    Language:Circom131