endorlabs / github-actionLinks
A GitHub action you can use to scan with Endor Labs
☆45Updated 4 months ago
Alternatives and similar repositories for github-action
Users that are interested in github-action are comparing it to the libraries listed below
Sorting:
- The model for the information captured in SPDX version 3 standard.☆90Updated last week
- Resources for the deps.dev API☆330Updated last week
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆325Updated 2 years ago
- OASIS SARIF TC: Repository for development of the draft standard, where requests for modification should be made via Github Issues☆186Updated this week
- SARIF Microsoft Visual Studio Code extension☆118Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆230Updated 11 months ago
- Enrich SBOMs with data from third party services☆179Updated this week
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆161Updated last week
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆404Updated 2 weeks ago
- in-toto Enhancements☆19Updated 5 months ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆95Updated this week
- OpenVEX Specification☆155Updated last month
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Updated 2 years ago
- ☆21Updated last month
- Collection of tools for analyzing open source packages.☆347Updated last week
- Go library for Sigstore signing and verification☆75Updated last week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆35Updated 2 months ago
- Tool to determine metrics for specified npm packages and/or JavaScript github repos☆15Updated last year
- in-toto Attestation Framework☆284Updated last month
- SPDX Merge tool☆45Updated 3 months ago
- Purpose-built security agent for hosted runners☆37Updated 2 months ago
- User-friendly documentation for the SARIF file format.☆316Updated last year
- Utility that provides an API and CLI to identify licenses and legal terms☆50Updated 2 weeks ago
- SBOM Edit - Conditional edits and merging of SBOMs☆74Updated 3 weeks ago
- ☆62Updated last year
- Software Supply Chain Security Platform☆343Updated this week
- A CLI tool for creating secure by design/default source repos.☆26Updated 11 months ago
- Utility that converts SBOM documents from CycloneDX to SPDX☆34Updated last year
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Updated 2 years ago
- Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.☆106Updated 2 weeks ago