google / osv-scanner-actionLinks
☆47Updated last week
Alternatives and similar repositories for osv-scanner-action
Users that are interested in osv-scanner-action are comparing it to the libraries listed below
Sorting:
- Resources for the deps.dev API☆351Updated this week
- Orchestrate GitHub Actions Security☆300Updated this week
- Official GitHub Action for OpenSSF Scorecard.☆339Updated this week
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆134Updated this week
- Verify provenance from SLSA compliant builders☆289Updated 3 months ago
- GitHub token permissions Monitor and Advisor actions☆338Updated 3 weeks ago
- Generate SBOMs with gh CLI☆195Updated 5 months ago
- OSV-SCALIBR: A library for Software Composition Analysis☆528Updated this week
- Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded☆76Updated this week
- Open Source Vulnerability schema.☆213Updated last week
- Format agnostic SBOM tooling☆119Updated 2 weeks ago
- Purpose-built security agent for hosted runners☆38Updated 2 months ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆235Updated last week
- Enrich SBOMs with data from third party services☆196Updated 2 months ago
- GitHub Action that given an organization or repository, produces information about the contributors over the specified time period.☆129Updated last week
- Publish a signed build provenance from your GitHub Actions workflow☆63Updated last year
- Throw a tag at it and it comes back with a checksum.☆150Updated this week
- ☆51Updated 3 weeks ago
- Runtime Security Solution for your CI/CD Pipeline☆110Updated 4 months ago
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆107Updated 3 months ago
- GitHub Action to enable automated security updates and open a issue/PR in repos in an org that have dependency files but no dependabot.ya…☆215Updated this week
- Language-agnostic SLSA provenance generation for Github Actions☆515Updated 2 weeks ago
- Go library for Sigstore signing and verification☆80Updated this week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆38Updated 5 months ago
- Find stale repositories in a GitHub organization.☆189Updated last week
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆905Updated last week
- Log monitor for Rekor to verify immutability and monitor entries☆37Updated last week
- Action for generating attestations for workflow artifacts☆61Updated last week
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆104Updated this week
- Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git☆137Updated this week