Suggest an alternative to

witness

Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.

Why do you think that https://github.com/sigstore/rekor is a good alternative to witness

A URL to the alternative repo (e.g. GitHub, GitLab)

Here you can share your experience with the project you are suggesting or its comparison with witness. Optional.

A valid email to send you a verification link when necessary or log in.