advanced-security / spdx-dependency-submission-actionLinks
upload an SPDX 2.2 formatted SBOM to GitHub's dependency submission API
☆19Updated this week
Alternatives and similar repositories for spdx-dependency-submission-action
Users that are interested in spdx-dependency-submission-action are comparing it to the libraries listed below
Sorting:
- Calculates dependencies for a Go build-target and submits the list to the Dependency Submission API☆74Updated 3 weeks ago
- ☆37Updated last week
- Privileged Requester Action☆23Updated 2 months ago
- Official GitHub Action for OpenSSF Scorecard.☆340Updated last week
- Action for generating attestations for workflow artifacts☆61Updated this week
- This tool allows GHES administrators to sync Actions to their instances☆133Updated 3 months ago
- ☆55Updated 3 weeks ago
- A TypeScript library for creating dependency snapshots.☆55Updated 3 weeks ago
- An Action for printing OIDC claims in GitHub Actions.☆116Updated 2 months ago
- Automatically open a pull request for repositories that have no CONTRIBUTING.md file☆41Updated 7 months ago
- Runs Dependabot Updates via GitHub Actions.☆111Updated last week
- Submit SBOMs to GitHub's dependency submission API☆16Updated 2 weeks ago
- The service side of clearlydefined.io☆50Updated this week
- Auto-generating docs repository for Renovate Bot☆57Updated this week
- Synchronize GitHub Code Scanning alerts to Jira issues☆95Updated 3 weeks ago
- Reusable workflows for developing actions☆74Updated last week
- Example of using Actions OIDC token to proxy into a private network☆103Updated 8 months ago
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆98Updated last month
- About GitHub Actions runner images provided by 3rd parties☆206Updated last week
- Run ORT in your GitHub action workflow to do licensing, security and best practices checks and generate reports/SBOMs☆33Updated last month
- Action for generating SBOM attestations for workflow artifacts☆41Updated last week
- A Github Action that can sync secrets from one repository to many others.☆328Updated last year
- A GitHub App that allows you to contribute upstream using private mirrors of public projects☆175Updated last week
- Find stale repositories in a GitHub organization.☆190Updated 2 weeks ago
- A GitHub Action to generate a report that contains code frequency metrics and programming languages used per repository belonging to a Gi…☆10Updated 2 years ago
- Generate SBOMs with gh CLI☆196Updated 6 months ago
- A tool for testing and debugging Dependabot update jobs.☆369Updated last week
- 🎯 Automatically add reviewers/assignees to issues/PRs☆51Updated last year
- OASIS SARIF TC: Repository for development of the draft standard, where requests for modification should be made via Github Issues☆188Updated last week
- GitHub Action that given an organization or repository, produces information about the contributors over the specified time period.☆134Updated last week