Supply Chain Sbom Provenance

SBOM generation and provenance verification for research software releases. Use when reviewing or writing release workflows that publish to PyPI, npm, GHCR, or similar registries; when verifying a downstream artifact's signatures or attestations; or when evaluating SLSA level for a release pipeline. Covers CycloneDX/SPDX SBOM generation with syft, Sigstore keyless signing with cosign, npm provenance, and SLSA build levels.

uw-ssec 8d8224c 4 files · 17.4 KB Updated

File contents

uw-ssec/rse-plugins/tree/main/plugins/supply-chain-security/skills/supply-chain-sbom-provenance commit 8d8224ce51

Frequently asked questions

npx skillmds add uw-ssec/supply-chain-sbom-provenance