google / oss-rebuildLinks
Securing open-source package ecosystems by originating, validating, and augmenting build attestations.
☆657Updated this week
Alternatives and similar repositories for oss-rebuild
Users that are interested in oss-rebuild are comparing it to the libraries listed below
Sorting:
- Vanir is a source code-based static analysis tool that automatically identifies the list of missing security patches in the target system…☆341Updated 2 months ago
- OSV-SCALIBR: A library for Software Composition Analysis☆516Updated last week
- A security layer for Git repositories☆547Updated this week
- HTTP(s) request filter for processes☆750Updated last week
- Kingfisher is a blazingly fast and highly accurate tool for secret detection and live validation across files, Git repos, GitHub, GitLab,…☆598Updated this week
- Resources for the deps.dev API☆345Updated last week
- Security scanner for MCP servers☆528Updated 5 months ago
- Protect against malicious open source packages 🤖☆802Updated last week
- ☆449Updated last month
- Globstar is a fast, feature-rich, and open-source static analysis toolkit for writing and running code checkers. Based on tree-sitter.☆459Updated 3 months ago
- Dockerfile formatter. a modern dockfmt.☆552Updated 2 weeks ago
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆896Updated this week
- Format agnostic SBOM tooling☆116Updated last week
- Verify provenance from SLSA compliant builders☆288Updated 2 months ago
- diff for Docker and OCI container images☆500Updated this week
- Programmatic sandboxing tool☆250Updated this week
- Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git☆133Updated last week
- ☆47Updated this week
- Validate the isolation posture of your container environment.☆300Updated 2 months ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆233Updated this week
- A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs☆416Updated this week
- OpenVEX Specification☆160Updated 4 months ago
- Prevent merging of malicious code in pull requests☆236Updated 7 months ago
- ICANN implementation of the Registry Data Access Protocol (RDAP)☆396Updated last week
- Reference implementation of OpenPubkey☆861Updated 2 months ago
- vet is a command-line tool that acts as a safety net for the risky curl | bash pattern. It lets you inspect, diff against previous versio…☆963Updated 2 months ago
- Common go library shared across sigstore services and clients☆489Updated this week
- Throw a tag at it and it comes back with a checksum.☆150Updated this week
- Declarative secrets, every environment, any provider.☆289Updated last month
- a simple wrapper around curl to easily download files☆432Updated 3 weeks ago