SOFTWARE · TRUSTED DATASET

GitHub activity, signed

Notable GitHub releases and security advisories, each record signed at the moment of contact.

WHAT IT IS

GitHub activity as a signed feed: notable releases and high or critical security advisories, read continuously and signed at the moment of contact. A developer agent tracking a dependency gets a reading with a receipt, checkable against the source.

Source
GitHub
Read & signed
continuously
Delivery
Signed slices, Extract API

EVERY ROW CARRIES A RECEIPT

DRM3 reads GitHub and signs each row at the moment of contact, on its own key. The receipt names the source and the time and chains to the one before it. A signature proves who recorded the row and that it has not changed; it does not certify the figure is correct, so you get a source to check and a chain to follow.

Pull this dataset into your agent, with a receipt on every slice.