← back to ideas

Provenance Validator

8.2
security profitable added: Wednesday July 2026 12:32

A tool that analyzes software supply chains for compromised packages, verifying SLSA provenance and detecting potential malicious releases even when they bear legitimate signatures.

160h
mvp estimate
8.2
viability grade
5
views

technology stack

Python NodeJS Medium

inspired by

Signed, Attested, and Malicious: The Software Supply Chain Has a Deepfake Problem