GrafeasAn open artifact metadata API to audit and govern your software supply chain Metadata for software supply chain Software supply chains can be described by distinct stages in the software lifecycle, including but not limited to: source, build, test, static analysis (e.g. compliance, vulnerabilities), deploy, and production monitoring. Grafeas provides a canonical representation of metadata f