google / oss-rebuildLinks
Securing open-source package ecosystems by originating, validating, and augmenting build attestations.
☆670Updated this week
Alternatives and similar repositories for oss-rebuild
Users that are interested in oss-rebuild are comparing it to the libraries listed below
Sorting:
- OSV-SCALIBR: A library for Software Composition Analysis☆537Updated this week
- Vanir is a source code-based static analysis tool that automatically identifies the list of missing security patches in the target system…☆342Updated last month
- A security layer for Git repositories☆557Updated last week
- HTTP(s) request filter for processes☆794Updated 2 weeks ago
- Kingfisher is a blazingly fast and highly accurate tool for secret detection and live validation across files, Git repos, GitHub, GitLab,…☆627Updated this week
- Resources for the deps.dev API☆354Updated last week
- Protect against malicious open source packages 🤖☆846Updated this week
- Globstar is a fast, feature-rich, and open-source static analysis toolkit for writing and running code checkers. Based on tree-sitter.☆464Updated 4 months ago
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆920Updated last week
- Dockerfile formatter. a modern dockfmt.☆566Updated last month
- ICANN implementation of the Registry Data Access Protocol (RDAP)☆412Updated 2 weeks ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆243Updated last week
- ☆47Updated last week
- ☆451Updated 2 months ago
- Common go library shared across sigstore services and clients☆491Updated last week
- Format agnostic SBOM tooling☆122Updated last week
- Security scanner for MCP servers☆528Updated 7 months ago
- Prevent merging of malicious code in pull requests☆239Updated 8 months ago
- like gofmt, but for jq☆377Updated 4 months ago
- vet is a command-line tool that acts as a safety net for the risky curl | bash pattern. It lets you inspect, diff against previous versio…☆969Updated 3 months ago
- A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs☆419Updated last week
- Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git☆136Updated last week
- Programmatic sandboxing tool☆258Updated last week
- #supply #chain #attack #detection☆566Updated last week
- OpenVEX Specification☆162Updated 5 months ago
- Qtap: An eBPF agent that captures pre-encrypted network traffic, providing rich context about egress connections and their originating pr…☆1,364Updated last week
- Verify provenance from SLSA compliant builders☆293Updated last week
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆407Updated this week
- A universal SBOM representation in protocol buffers☆307Updated last week
- A flexible threat detection platform that simplifies rule management and deployment using K8s CronJob and Helm, but can also run standalo…☆383Updated last year