coreinfrastructure / best-practices-badgeLinks
🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
☆1,294Updated this week
Alternatives and similar repositories for best-practices-badge
Users that are interested in best-practices-badge are comparing it to the libraries listed below
Sorting:
- Python reference implementation of The Update Framework (TUF)☆1,683Updated last week
- Fast, portable and reliable dependency analysis for any codebase. Supports license & vulnerability scanning for large monoliths. Langua…☆1,435Updated this week
- Now stored here:☆408Updated 4 years ago
- Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dock…☆1,004Updated last year
- A community version of the Open Decision Framework - A flexible, open approach to making decisions and leading projects☆833Updated last month
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆945Updated this week
- A Ruby Gem to detect under what license a project is distributed.☆861Updated this week
- Repolinter, The Open Source Repository Linter☆460Updated 2 months ago
- Curated list of awesome tools for managing open source programs☆487Updated 3 weeks ago
- A proposed standard that allows websites to define security policies.☆1,840Updated 2 years ago
- Gives criticality score for an open source project☆1,405Updated 6 months ago
- A Ruby gem to cache and verify the licenses of dependencies☆1,017Updated this week
- Notary is a project that allows anyone to have trust over arbitrary collections of data☆3,284Updated last year
- Mozilla HTTP Observatory☆1,850Updated last year
- Template for writing your own contributing guide☆728Updated 3 years ago
- The Open Source Survey☆531Updated 9 months ago
- LGTM is a simple pull request approval system [ARCHIVE]☆989Updated 7 years ago
- Source for TrunkBasedDevelopment.com☆527Updated 2 months ago
- A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby☆908Updated this week
- 📅 The web's go-to resource for Calendar Versioning info.☆546Updated last year
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆439Updated this week
- These patterns document how to apply open source principles and practices for software development within the confines of an organization…☆829Updated this week
- OpenSSF Security Tooling Working Group☆318Updated 4 months ago
- GitHub App that enforces the Developer Certificate of Origin (DCO) on Pull Requests☆329Updated 2 weeks ago
- Helping allocate resources to secure the critical open source projects we all depend on.☆377Updated 6 months ago
- OpenSSF Scorecard - Security health metrics for Open Source☆5,134Updated this week
- Artifact Metadata API☆1,551Updated 2 weeks ago
- in-toto is a framework to protect supply chain integrity.☆957Updated this week
- Memorable site for testing clients against bad SSL configs.☆2,968Updated last year
- The System Package Data Exchange (SPDX) specification in Markdown and HTML formats.☆345Updated last week