Provenance for the box
you actually own.
You install software on your home boxes from six different package managers and have no idea what's actually running. Attestree gives you one inventory, real update rings, and signed provenance — free to run at home, early-access today.
- winget Microsoft.PowerToys0.81.1 sig:9c4f…
- scoop main/neovim0.10.0 sig:1ab2…
- choco firefox125.0.1 sig:bd71…
- npm @anthropic-ai/sdk0.21.4 sig:e45a…
- pip requests2.31.0 sig:0fa9…
- dotnet aspirate0.10.0 sig:7c33…
Three things homelabbers ask us about first.
One inventory, every manager
Winget, Chocolatey, Scoop, npm, pip, .NET tools, and PowerShell Gallery — unified into a single attested view of what is on your boxes.
Real update rings at home
Canary, broad, and frozen rings for driver and BIOS updates without an enterprise license. Roll back from a single signed policy file.
Apache-2.0 installer shim
A SYSTEM- and user-context shim that fronts every Windows package manager. Apache-2.0 via GitHub release or build-from-source — the public repo lands M3–M6.
The products you'll actually run on your bench.
Inventory and Windows Updates are first up. Driver and firmware rings follow. Everything starts on a single node and federates when you add more.
Inventory
Single source of truth across winget, Choco, npm, pip, .NET, PSGallery.
Read productDrivers
Driver update rings with WHQL + provenance verification.
Read productFirmware
BIOS / UEFI update orchestration with vendor signatures pinned.
Read productWindows Updates
Approve, stage, and attest every KB before deployment.
Read productWinget Enterprise
Attested install gates in front of every Windows package channel.
Read productFree Community Edition.
A free Community Edition Docker image — closed-source (EULA), 50-endpoint cap, early-access / pre-GA. Plus an Apache-2.0 installer shim you build from source.
Or: Apache-2.0 winget-system-shim — GitHub release · build-from-source (public repo lands M3–M6)
"Design partner pipeline open. Be first to be quoted."