← Back to feed
Policy & RegulationEmerging1 sourceAug 10, 2026 · 05:30via Help Net Security

Chainloop: Open-source evidence store and policy engine for the software supply chain

Brief

Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be checked afterward.

Compliance and security teams get a control plane … More →

The post Chainloop: Open-source evidence store and policy engine for the software supply chain appeared first on Help Net Security .

Read more on Help Net Security