google / oss-rebuild
Securing open-source package ecosystems by originating, validating, and augmenting build attestations.
☆32Updated last week
Related projects ⓘ
Alternatives and complementary repositories for oss-rebuild
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated last week
- Supply Chain Query Tool☆13Updated 2 years ago
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- TACOS framework structural details☆20Updated 11 months ago
- ☆22Updated 2 years ago
- OpenVEX Specification☆131Updated 4 months ago
- ☆95Updated this week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Format agnostic SBOM tooling☆81Updated this week
- ☆9Updated 7 months ago
- SPDX Merge tool☆39Updated 2 months ago
- A specification for signing methods and formats used by Secure Systems Lab projects.☆68Updated 2 months ago
- ☆74Updated 3 months ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- ☆26Updated this week
- An query language and interactive tooling to work with SBOM data.☆14Updated last month
- Technical Advisory Council☆109Updated this week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆30Updated 10 months ago
- The model for the information captured in SPDX version 3 standard.☆71Updated this week
- Go module to generate and transform VEX documents☆34Updated 3 weeks ago
- ☆18Updated 5 months ago
- ☆56Updated 2 years ago
- Compare vulnerability scanners results (to make them better!)☆15Updated this week
- A CLI tool for creating secure by design/default source repos.☆24Updated 3 months ago
- Automatically assess and score software repositories for supply chain risk.☆79Updated this week
- Specification and other related documents.☆40Updated 6 months ago
- A tool to check the security settings of Github Organizations.☆69Updated last year
- A TUF repository and signing tool☆22Updated this week
- ☆61Updated 4 months ago
- VINCE is the Vulnerability Information and Coordination Environment developed and used by the CERT Coordination Center to improve coordin…☆59Updated 3 weeks ago