Witness
Pluggable framework that automates, normalizes, and verifies software artifact provenance.
Pluginfreeglobal

Witness is a pluggable framework for software supply chain risk management, originating at TestifySec and now maintained as part of the CNCF in-toto ecosystem. It automates the collection of attestations during a build pipeline, normalizes that provenance data, and verifies it against policy so teams can prove what went into a software artifact and catch tampering.
Categories
securitysupply chain securityci/cd
Something wrong with this listing — dead link, not a real product, wrong info?

