k2gl/in-toto-attestation dependents (2) Order by: name | downloads Show: all | require | require-dev

  • PHP

    k2gl/sigstore-verify

    Offline, fail-closed PHP verifier for Sigstore bundles: Fulcio certificate chain, DSSE or message signature, Rekor v1/v2 transparency-log proof, RFC 3161 timestamp, certificate transparency and identity policy. Passes the official sigstore-conformance suite.

    Latest version requires k2gl/in-toto-attestation ^1.0

  • PHP

    k2gl/slsa-provenance

    Faithful, typed PHP implementation of the SLSA Provenance v1 and v0.2 predicates, built on k2gl/in-toto-attestation.

    Latest version requires k2gl/in-toto-attestation ^1.1