advanced-security / spdx-dependency-submission-actionLinks
upload an SPDX 2.2 formatted SBOM to GitHub's dependency submission API
☆18Updated 2 weeks ago
Alternatives and similar repositories for spdx-dependency-submission-action
Users that are interested in spdx-dependency-submission-action are comparing it to the libraries listed below
Sorting:
- An Action for printing OIDC claims in GitHub Actions.☆109Updated this week
- ☆51Updated this week
- Calculates dependencies for a Go build-target and submits the list to the Dependency Submission API☆64Updated 3 weeks ago
- Official GitHub Action for OpenSSF Scorecard.☆334Updated last week
- Action for generating SBOM attestations for workflow artifacts☆38Updated 2 weeks ago
- Reusable workflows for developing actions☆72Updated 2 weeks ago
- A TypeScript library for creating dependency snapshots.☆50Updated last week
- Submit SBOMs to GitHub's dependency submission API☆16Updated 2 years ago
- GitHub Action for submitting Maven dependencies☆53Updated last week
- GitHub Action to get a user teams membership in a given organization☆32Updated last month
- Runs Dependabot Updates via GitHub Actions.☆107Updated this week
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆96Updated last year
- Auto-generating docs repository for Renovate Bot☆57Updated this week
- GitHub API client for GitHub Actions☆200Updated this week
- The service side of clearlydefined.io☆49Updated last week
- ☆32Updated last year
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆103Updated last month
- GitHub Action for creating software bill of materials using Syft.☆202Updated this week
- ☆30Updated last week
- Action for generating attestations for workflow artifacts☆59Updated last week
- This tool allows GHES administrators to sync Actions to their instances☆129Updated last week
- Synchronize GitHub Code Scanning alerts to Jira issues☆92Updated this week
- Checkmarx CxFlow GitHub Action with SARIF output☆54Updated 4 months ago
- Find stale repositories in a GitHub organization.☆186Updated this week
- ☆81Updated last year
- This action uploads and scans code to Veracode for a static policy (or sandbox) scan.☆33Updated 2 months ago
- Generate SBOMs with gh CLI☆193Updated 3 months ago
- OASIS SARIF TC: Repository for development of the draft standard, where requests for modification should be made via Github Issues☆187Updated last week
- GitHub Actions Importer helps you plan and automate the migration of Azure DevOps, Bamboo, CircleCI, GitLab, Jenkins, and Travis CI pipel…☆57Updated last year
- An OIDC client to retrieve a GitHub API scoped token from within an Actions workflow☆30Updated last year