I helped create Witness, donated it to the CNCF/in-toto ecosystem, and worked on the NIST 800-204D "pipeline observer" guidance. CI/Lock is the next version of that work, and it's under the Apache 2. 0 license.

Source: [Hacker News](https://cilock.dev/)

Sponsored