Chainloop: Open-source evidence store and policy engine for the software supply chain

Aug 10, 2026 - 07:45
Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be checked afterward. Compliance and security teams get a control plane … More

The post Chainloop: Open-source evidence store and policy engine for the software supply chain appeared first on Help Net Security.