Submit SBOMs to GitHub's dependency submission API
☆18Dec 4, 2025Updated 5 months ago
Alternatives and similar repositories for sbom-dependency-submission-action
Users that are interested in sbom-dependency-submission-action are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl…☆11Apr 14, 2026Updated 3 weeks ago
- Example repository that demonstrates a supply chain security workflow using Syft, Grype, Cosign☆12Sep 15, 2021Updated 4 years ago
- Github Action implementation of SLSA Provenance Generation☆50Apr 27, 2026Updated last week
- go-ima is a tool that checks if a file has been tampered with. It is useful in ensuring integrity in CI systems☆14Sep 28, 2023Updated 2 years ago
- Known vulnerability scanning for your GitHub repository using CVE Binary Tool. This Action can scan binaries, component lists and SBOMs …☆14Oct 20, 2025Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations☆60May 2, 2026Updated last week
- my goreleaser.yml files☆13Apr 9, 2026Updated last month
- ☆57Jun 1, 2022Updated 3 years ago
- Bitcoin Knots release attestations (Guix)☆19Updated this week
- upload an SPDX 2.2 formatted SBOM to GitHub's dependency submission API☆24Apr 27, 2026Updated last week
- Demo app duplicated in 5 languages (Go/JavaScript/Python/Ruby/Rust) showing how to go from source code to container image using melange+a…☆37Dec 24, 2023Updated 2 years ago
- SLSA level 3 action☆11Apr 26, 2024Updated 2 years ago
- Functionality and DataModels of OWASP CycloneDX for PHP☆13May 1, 2026Updated last week
- ☆11Nov 11, 2022Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Publish a signed build provenance from your GitHub Actions workflow☆62May 21, 2024Updated last year
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆45Oct 30, 2023Updated 2 years ago
- ☆14Nov 13, 2023Updated 2 years ago
- Generate Software Bill of Materials for R Things☆20Feb 9, 2024Updated 2 years ago
- To manage Docker Content Trust and Notary certificates☆13May 1, 2026Updated last week
- Comparison of Chainguard Images to others☆21Updated this week
- Help protect against malicious build scripts☆27Updated this week
- Docker CI scripts☆12Nov 24, 2025Updated 5 months ago
- Performant source for RPM repositories metadata https://github.com/gridhead/metasource☆12Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Measure release insights and recommendations for open-source dependencies. Note: this project is archived.☆10Jan 3, 2023Updated 3 years ago
- Various tools, images, etc. to support the Wolfi OSS project☆27Apr 30, 2026Updated last week
- Go beyond package manager discovery for SBOM☆18Feb 22, 2022Updated 4 years ago
- GitHub action to generate a CycloneDX SBOM for .NET☆12Jul 15, 2025Updated 9 months ago
- CLI util: Poor man's rpath for Windows executables.☆12Dec 16, 2018Updated 7 years ago
- ☆20Apr 30, 2026Updated last week
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆73Updated this week
- Easy way how to add Quarkus extensions to your Keycloak deployment☆20Apr 13, 2026Updated 3 weeks ago
- ☆21Apr 25, 2026Updated last week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Rez CLI/GUI tool for installing packages from developer package repositories.☆12Nov 25, 2021Updated 4 years ago
- Preview the gcloud api with fzf.☆26Aug 17, 2024Updated last year
- A Pipeline Configuration that marries two great tools - Rez and Shotgun☆12Dec 3, 2018Updated 7 years ago
- GitHub action to produce a SBOM report from a given Black Duck project☆12Feb 5, 2026Updated 3 months ago
- Create SBOMs in CycloneDX format for your Vite or Rollup projects with ease☆23Updated this week
- A taxonomy of all official CycloneDX property namespaces and names☆21Mar 2, 2026Updated 2 months ago
- GitHub actions for the chainguard-images☆21Apr 27, 2026Updated last week