Offline, fail-closed PHP verifier for Sigstore bundles: certificate chain to a Fulcio root, DSSE signature, Rekor transparency-log proof and identity policy, returning a verified in-toto Statement.
71%
Total Score
95
19
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
k2gl/tuf Version ^1.0 | — | — |
phpseclib/phpseclib Version ^3.0 | — | — |
k2gl/in-toto-attestation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant