from pkg/DESCR:
in-toto provides a framework to protect the integrity of the software supply chain. It does so by verifying that each task in the chain is carried out as planned, by authorized personnel only, and that the product is not tampered with in transit.Haven't tinkered around with building 'layouts' yet, but thought I would submit to ports@ to see if there's any interest.
There's one currently unported RUN_DEPEND security/py-securesystemslib which I'll send after this email.
g
py-in-toto-1.2.0.tgz
Description: Binary data