Provenance Validator
8.2
A tool that analyzes software supply chains for compromised packages, verifying SLSA provenance and detecting potential malicious releases even when they bear legitimate signatures.
160h
mvp estimate
8.2
viability grade
5
views
technology stack
Python
NodeJS
Medium
inspired by
Signed, Attested, and Malicious: The Software Supply Chain Has a Deepfake Problem