CI/lock – supply-chain attestation CLI, from the Witness creators
From Witness/in-toto creators, keyless attestation blocks poisoned CI runs.
"From each according to their updates, to each according to their needs"
Self-hosted patch manager for homelabs, but Ansible and Spacewalk already solve this.
Homelab enthusiasts and sysadmins managing small server fleets
Ansible · Spacewalk · WSUS
From Witness/in-toto creators, keyless attestation blocks poisoned CI runs.
Deterministic dependency review with cross-stack scanning, but Dependabot, Snyk, and Renovate dominate CI dependency automation.
Dependabot alternative with AI test generation and supply chain poisoning checks.
Self-healing homelab with backup drills—no SSH or dashboards required.
Backup Drill verifies restores automatically, unlike Portainer's silent backups.
Backup drill feature actually tests restores instead of just assuming they work.