google / oss-rebuildLinks
Securing open-source package ecosystems by originating, validating, and augmenting build attestations.
☆674Updated this week
Alternatives and similar repositories for oss-rebuild
Users that are interested in oss-rebuild are comparing it to the libraries listed below
Sorting:
- A security layer for Git repositories☆571Updated this week
- OSV-SCALIBR: A library for Software Composition Analysis☆560Updated last week
- HTTP(s) request filter for processes☆815Updated 3 weeks ago
- Resources for the deps.dev API☆376Updated this week
- Dockerfile formatter. a modern dockfmt.☆584Updated 3 months ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆301Updated this week
- Verify provenance from SLSA compliant builders☆304Updated 2 months ago
- Globstar is a fast, feature-rich, and open-source static analysis toolkit for writing and running code checkers. Based on tree-sitter.☆474Updated 6 months ago
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆951Updated this week
- like gofmt, but for jq☆384Updated 3 weeks ago
- Security scanner for MCP servers☆545Updated 9 months ago
- Format agnostic SBOM tooling☆131Updated 2 months ago
- Common go library shared across sigstore services and clients☆496Updated last week
- ICANN implementation of the Registry Data Access Protocol (RDAP)☆423Updated this week
- [Experimental] jail for Go modules☆113Updated last week
- ☆62Updated 2 weeks ago
- Programmatic sandboxing tool☆263Updated this week
- Keyless Git signing using Sigstore☆1,052Updated this week
- Kingfisher is a blazingly fast and highly accurate tool for secret detection and live validation across files, Git repos, GitHub, GitLab,…☆784Updated last week
- A universal SBOM representation in protocol buffers☆315Updated last week
- vet is a command-line tool that acts as a safety net for the risky curl | bash pattern. It lets you inspect, diff against previous versio…☆975Updated 5 months ago
- ☆140Updated last week
- A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs☆428Updated last week
- GitHub token permissions Monitor and Advisor actions☆351Updated 2 months ago
- Simplified executable deployment☆802Updated this week
- diff for Docker and OCI container images☆545Updated this week
- Language-agnostic SLSA provenance generation for Github Actions☆542Updated 3 months ago
- OpenVEX Specification☆164Updated 2 weeks ago
- ☆456Updated 4 months ago
- Extract +700 technologies from any repository. Detect Languages, SaaS, Cloud, Infrastructure, Dependencies and Services☆394Updated last week