SOFTWARE · TRUSTED DATASET
GitHub activity, signed
Notable GitHub releases and security advisories, each record signed at the moment of contact.
WHAT IT IS
GitHub activity as a signed feed: notable releases and high or critical security advisories, read continuously and signed at the moment of contact. A developer agent tracking a dependency gets a reading with a receipt, checkable against the source.
- Source
- GitHub
- Read & signed
- continuously
- Delivery
- Signed slices, Extract API
EVERY ROW CARRIES A RECEIPT
DRM3 reads GitHub and signs each row at the moment of contact, on its own key. The receipt names the source and the time and chains to the one before it. A signature proves who recorded the row and that it has not changed; it does not certify the figure is correct, so you get a source to check and a chain to follow.
Pull this dataset into your agent, with a receipt on every slice.
