Cryptographically sign your SBOM with ECDSA-P521 + RFC 3161 timestamps. Tamper-evident, publicly verifiable. One GitHub Action step. EU CRA-ready.
ecdsa spdx devsecops rfc3161 sbom github-actions cyclonedx supply-chain-security cyclonedx-sbom cryptographic-signing eu-cra sigstore-alternative
-
Updated
May 26, 2026 - TypeScript