k2gl/in-toto-attestation dependents (2) Order by: name | downloads Show: all | require | require-dev
-
PHP
k2gl/sigstore-verify
Offline, fail-closed PHP verifier for Sigstore bundles: certificate chain to a Fulcio root, DSSE signature, Rekor transparency-log proof and identity policy, returning a verified in-toto Statement.
-
PHP
k2gl/slsa-provenance
Faithful, typed PHP implementation of the SLSA Provenance v1 and v0.2 predicates, built on k2gl/in-toto-attestation.