google / oss-rebuildLinks
Securing open-source package ecosystems by originating, validating, and augmenting build attestations.
☆674Updated last week
Alternatives and similar repositories for oss-rebuild
Users that are interested in oss-rebuild are comparing it to the libraries listed below
Sorting:
- Vanir is a source code-based static analysis tool that automatically identifies the list of missing security patches in the target system…☆343Updated 2 months ago
- OSV-SCALIBR: A library for Software Composition Analysis☆547Updated this week
- HTTP(s) request filter for processes☆809Updated this week
- A security layer for Git repositories☆563Updated this week
- Resources for the deps.dev API☆366Updated last week
- Dockerfile formatter. a modern dockfmt.☆573Updated 2 months ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆288Updated this week
- ☆454Updated 3 months ago
- Security scanner for MCP servers☆539Updated 8 months ago
- Format agnostic SBOM tooling☆127Updated last month
- ICANN implementation of the Registry Data Access Protocol (RDAP)☆422Updated this week
- Kingfisher is a blazingly fast and highly accurate tool for secret detection and live validation across files, Git repos, GitHub, GitLab,…☆708Updated last week
- Throw a tag at it and it comes back with a checksum.☆151Updated this week
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆935Updated last week
- Validate the isolation posture of your container environment.☆307Updated last week
- like gofmt, but for jq☆380Updated 5 months ago
- Protect against malicious open source packages 🤖☆924Updated last week
- Programmatic sandboxing tool☆261Updated this week
- Verify provenance from SLSA compliant builders☆301Updated last month
- Backend for HTTP Observatory on MDN☆100Updated last week
- Globstar is a fast, feature-rich, and open-source static analysis toolkit for writing and running code checkers. Based on tree-sitter.☆475Updated 5 months ago
- Common go library shared across sigstore services and clients☆493Updated last week
- OpenVEX Specification☆164Updated 6 months ago
- ☆221Updated last year
- diff for Docker and OCI container images☆531Updated last week
- Common Release Data for various projects in a consumable format, automatically updated.☆190Updated this week
- A universal SBOM representation in protocol buffers☆314Updated this week
- vet is a command-line tool that acts as a safety net for the risky curl | bash pattern. It lets you inspect, diff against previous versio…☆975Updated 4 months ago
- #supply #chain #attack #detection☆635Updated this week
- A proposal to restrict sites from accessing a users' local network without permission☆256Updated last month