Software Supply Chain
Standards in the catalog that belong to software supply chain — 6 of them. A standard is listed here only when it is specific to this industry; the general-purpose ones it also relies on, like HTTP, OAuth and JSON Schema, deliberately carry no domain.
The same industry, as data models
3 data models define what information exists in software supply chain, as opposed to the standards applied in API operations listed below. Same industry, two lenses.
See the software supply chain data models →| Standard | What it is |
|---|---|
| Notary Project Signature Specification | The Notary Project signature specification defines a portable signature envelope for OCI artifacts and blobs, along with how those signatures are s... |
| OpenChain | OpenChain is a Linux Foundation project defining conformance requirements for open-source license-compliance and security-assurance programs, ratif... |
| SLSA | SLSA (Supply-chain Levels for Software Artifacts) is a security framework and specification of progressive levels for hardening software build and ... |
| Sigstore | Sigstore is an open standard and set of tools for signing, verifying, and proving the provenance of software artifacts. It provides keyless signing... |
| The Update Framework (TUF) | The Update Framework is a graduated CNCF specification for securing software update systems. It defines a set of signed JSON metadata roles and a c... |
| in-toto | in-toto is a framework and specification for cryptographically verifying the integrity of a software supply chain. It captures and attests each ste... |