About this project

OpenFab is an open-source "software fab": natural language in, trustworthy software out. It takes a plain-language spec and produces a working product where every artifact carries a reproducible build, signed provenance, and AI/Human attribution, running on a swappable agent base and a swappable forge. It composes existing open standards (SLSA, in-toto, Sigstore, DID) rather than inventing new ones; the claimed durable value is the integrated pipeline plus the process and decision memory it emits. The repository is the Phase-0 hand-built MVP (v0.1, with a v0.3 build described in the README), written in Rust. Documentation points to an overview, a value-proposition delta versus existing tools, an MVP design/PRD, and an AGENTS.md contributor guide. Workflow: a natural-language intent is turned by the LLM base into a versioned spec plus machine-checkable acceptance criteria; the base writes the app; acceptance checks run in a policy-gated sandbox; an in-toto/SLSA attestation with an `openfab/generation` predicate is signed with did:key; provenance is committed in-repo; a PR opens; a trust gate blocks merge until N-of-M maintainer sign-off; then `openfab verify` re-checks signatures, recorded acceptance, and sign-off. A feedback command folds human notes into spec v→v+1. Interfaces: a web UI (`openfab serve`, also available as a no-install browser demo) and a CLI with commands including run, attest, signoff, verify, verify-file, feedback, maintainer-add, reputation, and list. `openfab attest` signs and gates code an external AI agent factory already produced, without generation. Architecture: a base/forge-independent Core (spec, identity, provenance, sbom, trust, reputation, conformance), ports (BasePort, ForgePort), and adapters. Six bases are listed (claude, codex, AgentScope, HiClaw, agent-chat, OpenHands) and four forges (GitHub, Forgejo, Gitea, GitCode), with offline local instances when credentials are absent. The README states 51 tests pass with fmt and clippy clean, and documents honest v0.1 limitations with named production swaps (e.g., Sigstore, OPA, Podman/gVisor, Syft, Nix). Licensed Apache-2.0.