{"repo":"crashappsec/chalk","free":true,"listed":false,"github":"https://github.com/crashappsec/chalk","clone":"git clone https://github.com/crashappsec/chalk.git","description":"Chalk allows you to follow code from development, through builds and into production.","language":"Nim","stars":438,"topics":["cicd","containers","docker","elf","metadata","observability","security-tools"],"license":"GPL-3.0","category":"deployment-docker-iac","readme_excerpt":"Software provenance and attestation made easy Chalk gives you a cryptographically verifiable chain of custody from build through production, with minimal configuration, and no changes to how your software is run. Overview Chalk seamlessly handles provenance and attestation for production software, collecting detailed environmental info about software being built or run, cradle to grave. Correlating all that provenance information is the hard part. We handle this by adding a tamperproof identifier into all artifacts (the chalk mark ). The identifier is inert JSON; we can auto-insert into a containers, executables, JARs (and other ZIP-based archives), shell scripts and source for nearly all interpreted languages. Chalking never impacts execution. Automatically chalking software during the build process makes it trivial to do two things that can be a large source of enterprise pain: 1. Easily determine the integrity of individual artifacts. 2. Automatically correlate information collected about those artifacts at any point. When collecting attestation information, we handle a lot of plumbing transparently. For instance, we automatically apply Docker’s SBOM tooling when available, but will fall back to using a stand-alone OSS tool (Syft) when not available. Similarly, we collect cloud-specific metadata, probing for common cloud metadata interfaces. If you set up build signature mode, the build attestation will be signed using Sigstore, and automatically pushed to the container re","default_branch":null,"files":null,"tree":[],"storefront":"/r/crashappsec","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/crashappsec/chalk/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}