anchore / yardstick
Compare vulnerability scanners results (to make them better!)
☆16Updated this week
Alternatives and similar repositories for yardstick:
Users that are interested in yardstick are comparing it to the libraries listed below
- a fast changelog generator sourced from PRs and Issues☆53Updated last week
- ☆41Updated this week
- An SBOM query language and associated utilities☆54Updated 11 months ago
- Slack alert bot for matching Github Audit Events☆10Updated 2 months ago
- Static analysis for CloudFormation templates to identify common misconfiguration☆57Updated 2 years ago
- ☆27Updated this week
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆83Updated this week
- ☆11Updated 11 months ago
- vscode extension for tfsec☆30Updated 2 years ago
- Repository for the generation of OSCAL data types☆21Updated last week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆12Updated 3 months ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 2 months ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆77Updated this week
- SPDX Merge tool☆39Updated 4 months ago
- TACOS framework structural details☆20Updated last year
- ☆30Updated 2 months ago
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆23Updated last month
- Github Action implementation of SLSA Provenance Generation☆47Updated this week
- A repository containing Minder rules and profiles recommended by your friends at Stacklok☆19Updated this week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- Format agnostic SBOM tooling☆94Updated this week
- Log monitor for Rekor to verify immutability and monitor entries☆30Updated this week
- Publishes BOMs to Dependency-Track from GitHub Actions☆48Updated 3 months ago
- Grype vulnerability check plugin for Visual Studio Code☆22Updated last month
- Security advisory data for Wolfi☆13Updated this week
- Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.☆13Updated this week
- A CLI used to work with the Wolfi OSS project☆58Updated this week
- A tool to check the security settings of Github Organizations.☆70Updated last year
- Repository to archive GCP Documentation for local use☆13Updated 2 months ago