anchore / chronicleLinks
a fast changelog generator sourced from PRs and Issues
☆60Updated last week
Alternatives and similar repositories for chronicle
Users that are interested in chronicle are comparing it to the libraries listed below
Sorting:
- Compare vulnerability scanners results (to make them better!)☆16Updated last month
- Manage a directory of binaries without a package manager☆33Updated this week
- An SBOM query language and associated utilities☆54Updated last year
- Various tools, images, etc. to support the Wolfi OSS project☆24Updated last week
- Dynamic GitHub Actions from Wolfi packages☆43Updated last month
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆42Updated 2 years ago
- A CLI used to work with the Wolfi OSS project☆62Updated this week
- ☆50Updated last week
- ☆42Updated 7 months ago
- A sweet little formatter for YAML☆28Updated this week
- SPDX Merge tool☆45Updated last month
- Docs and Tutorials for Chainguard☆84Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆97Updated last week
- A collection of reusable Github Actions workflows.☆133Updated this week
- go library for processing container images and simulating a squash filesystem☆98Updated this week
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆99Updated this week
- ☆34Updated last year
- ☆29Updated this week
- Go library for Sigstore signing and verification☆68Updated this week
- Throw a tag at it and it comes back with a checksum.☆138Updated this week
- jq for .tf files (Terraform/OpenTofu)☆27Updated last year
- (d)ocker(f)ile (c)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆73Updated last week
- Search an SBOM for licenses and the packages they belong to☆92Updated last week
- Sigstore's Protocol Buffer specifications☆33Updated this week
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆63Updated this week
- ☆42Updated 2 years ago
- CLOWarden is a tool that manages access to resources across multiple services☆53Updated this week
- in-toto is a framework to secure the software supply chain.☆70Updated 5 months ago
- Grype vulnerability check plugin for Visual Studio Code☆23Updated 6 months ago
- A draft standard for communicating a cryptographic record of build inputs for software artifacts.☆24Updated 2 months ago