Nolabs AI
The team behind nono, made up of people who built Sigstore — the OpenSSF project for signing and verifying software artifacts that became standard infrastructure for open-source supply-chain provenance.
That lineage explains the shape of nono. Sigstore’s problem was “you’re running code, can you prove where it came from”; nono’s is “your agent is running tools, can you bound what they may touch.” Both answers are infrastructural rather than advisory: a verifiable artifact in one case, an enforced sandbox with proxied credentials in the other. Neither asks the thing being governed to cooperate.
It’s an unusual provenance for this wiki, where agent tooling mostly comes from AI labs, agent startups, or individual harness authors. Supply-chain security people arriving in the agent space is itself a signal about which problems are now considered load-bearing.
Ships an Apache-2.0 core with a public profile registry (registry.nono.sh) and an OpenSSF Best
Practices badge. No commercial product is described, though the README claims production use at
large companies without naming any nono.