secure-by-default github template for oss: signed commits, sha-pinned actions, slsa v1.0 provenance, sigstore keyless signing, npm oidc publishing.
-
Updated
Jun 23, 2026 - Shell
secure-by-default github template for oss: signed commits, sha-pinned actions, slsa v1.0 provenance, sigstore keyless signing, npm oidc publishing.
attested-delivery org site — the digest is the release. Signed, SLSA-attested, fail-closed-verified releases on GitHub-native tooling.
The promptsign command - a single static binary that signs, verifies, and enforces trust policy inside agent session hooks.
Sign AI instruction files from GitHub Actions with the workflow's own verified identity
Claude Code plugin that verifies signatures on skills and instruction files before they reach model context
Add a description, image, and links to the keyless-signing topic page so that developers can more easily learn about it.
To associate your repository with the keyless-signing topic, visit your repo's landing page and select "manage topics."