41 results found Sort:

226
1.6k
other
62
Supply-chain Levels for Software Artifacts
Created 2021-03-10
1,893 commits to main branch, last one a day ago
176
1.3k
apache-2.0
43
GUAC aggregates software security metadata into a high fidelity graph database.
Created 2022-06-10
1,690 commits to main branch, last one 23 hours ago
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container ima...
Created 2020-01-28
386 commits to master branch, last one 5 days ago
188
967
bsd-2-clause
31
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-...
Created 2017-11-27
1,102 commits to main branch, last one 11 months ago
63
775
apache-2.0
16
Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets
Created 2022-07-14
238 commits to main branch, last one about a month ago
36
629
agpl-3.0
10
Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
Created 2022-04-22
439 commits to main branch, last one 7 months ago
Network egress filtering and runtime security for GitHub-hosted and self-hosted runners
Created 2021-10-28
531 commits to main branch, last one 2 days ago
15
525
apache-2.0
67
Graphing SBOM's Fast.
Created 2024-06-05
127 commits to main branch, last one a day ago
29
375
apache-2.0
11
Chainloop is an Open Source evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, CSAF files, QA reports, and more.
Created 2023-03-06
1,041 commits to main branch, last one 20 hours ago
26
356
gpl-3.0
12
Independent verification of binary packages - reproducible builds
Created 2019-12-12
424 commits to main branch, last one a day ago
BLint is a Binary Linter to check the security properties, and capabilities in your executables. Since v2, blint is also an SBOM generator for binaries.
Created 2023-01-21
239 commits to main branch, last one 12 days ago
83
325
other
13
Docker Scout CLI
Created 2023-05-21
173 commits to main branch, last one 10 days ago
Orchestrate GitHub Actions Security
Created 2021-10-12
1,287 commits to main branch, last one 2 months ago
24
232
apache-2.0
7
boostsecurityio/poutine
Created 2024-04-09
158 commits to main branch, last one 16 hours ago
22
232
apache-2.0
8
Tool to achieve policy driven vetting of open source dependencies
Created 2022-12-30
472 commits to main branch, last one 2 days ago
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
Created 2020-03-26
386 commits to master branch, last one 20 days ago
Catalogue all images of a Kubernetes cluster to multiple targets with Syft
Created 2022-01-08
955 commits to main branch, last one about a month ago
21
186
apache-2.0
7
SBOM quality score - Quality metrics for your sboms
Created 2023-01-31
560 commits to main branch, last one 2 days ago
Small tool to inform you about potential risks in project dependencies list
Created 2022-03-25
26 commits to main branch, last one about a year ago
23
138
upl-1.0
10
Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks, detec...
Created 2022-12-05
464 commits to main branch, last one 2 months ago
12
130
gpl-3.0
2
List your dependencies capabilities and monitor if updates require more capabilities.
This repository has been archived (exclude archived)
Created 2022-01-11
34 commits to main branch, last one about a year ago
A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the ...
Created 2023-07-28
88 commits to main branch, last one 9 months ago
12
121
gpl-3.0
3
Signing-key abuse and update exploitation framework
Created 2022-10-16
330 commits to main branch, last one 7 days ago
6
101
apache-2.0
9
boostsecurityio/lotp
Created 2024-02-15
12 commits to main branch, last one 8 months ago
10
95
apache-2.0
6
Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance
Created 2023-01-12
330 commits to main branch, last one 9 months ago
Docker Scout GitHub Action
Created 2023-02-27
237 commits to main branch, last one 10 days ago
Runtime Security Solution for your CI/CD Pipeline
Created 2023-03-02
81 commits to main branch, last one 2 months ago
Experimental pacman integration for Reproducible Builds and Binary Transparency (with sigstore/rekor)
Created 2021-08-23
72 commits to main branch, last one 4 months ago
6
79
apache-2.0
11
Automatically assess and score software repositories for supply chain risk.
Created 2023-01-03
491 commits to main branch, last one 19 hours ago