coreinfrastructure / best-practices-badgeLinks
🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
☆1,298Updated last week
Alternatives and similar repositories for best-practices-badge
Users that are interested in best-practices-badge are comparing it to the libraries listed below
Sorting:
- The Open Source Discovery Service☆1,137Updated 3 weeks ago
- Python reference implementation of The Update Framework (TUF)☆1,688Updated last week
- Now stored here:☆408Updated 4 years ago
- Fast, portable and reliable dependency analysis for any codebase. Supports license & vulnerability scanning for large monoliths. Langua…☆1,440Updated this week
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆952Updated 2 weeks ago
- a community wiki for improving code quality☆347Updated last week
- A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby☆920Updated last week
- Curated list of awesome tools for managing open source programs☆487Updated last week
- Repolinter, The Open Source Repository Linter☆460Updated 2 weeks ago
- Mozilla HTTP Observatory☆1,851Updated last year
- Markdown lint tool☆1,966Updated last week
- Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dock…☆1,008Updated last year
- Notary is a project that allows anyone to have trust over arbitrary collections of data☆3,281Updated last year
- Your unofficial guide to doing dotfiles on GitHub.☆1,491Updated this week
- GitHub App that enforces the Developer Certificate of Origin (DCO) on Pull Requests☆328Updated last week
- Gives criticality score for an open source project☆1,408Updated 7 months ago
- 📅 The web's go-to resource for Calendar Versioning info.☆550Updated last year
- A brief tutorial on how to use Software Package Data Exchange (SPDX)☆139Updated last year
- The Update Framework specification☆394Updated last year
- A stupid game for learning about containers, capabilities, and syscalls.☆908Updated 2 years ago
- LGTM is a simple pull request approval system [ARCHIVE]☆990Updated 7 years ago
- An opinionated Dockerfile linter.☆1,024Updated 2 years ago
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆446Updated this week
- A Ruby gem to cache and verify the licenses of dependencies☆1,019Updated last week
- Validate links in awesome projects☆875Updated 2 years ago
- .travis.yml => build.sh converter☆658Updated 3 months ago
- These patterns document how to apply open source principles and practices for software development within the confines of an organization…☆833Updated last week
- Helping allocate resources to secure the critical open source projects we all depend on.☆377Updated 6 months ago
- An observatory for TLS configurations, X509 certificates, and more.☆541Updated 2 months ago
- Don't just present; interact with your audience!☆942Updated 8 months ago