google / osv-scanner-action
☆16Updated last week
Related projects ⓘ
Alternatives and complementary repositories for osv-scanner-action
- Publish a signed build provenance from your GitHub Actions workflow☆63Updated 5 months ago
- GitHub CLI extension for working with CodeQL☆30Updated 5 months ago
- Official GitHub Action for OpenSSF Scorecard.☆265Updated this week
- Action for generating SBOM attestations for workflow artifacts☆19Updated last week
- Entitlements plugin to manage GitHub Orgs and Team memberships and access☆21Updated last week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆32Updated 4 months ago
- Runner Container Hooks for GitHub Actions☆76Updated this week
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆33Updated this week
- Purpose-built security agent for hosted runners☆29Updated 3 months ago
- Entitlements plugin for a robust audit log☆20Updated last week
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆27Updated 5 months ago
- Privileged Requester Action☆15Updated last week
- GitHub CLI extension for generating a report on repository dependencies.☆45Updated last year
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆95Updated 6 months ago
- ☆42Updated last month
- GitHub Action for creating software bill of materials using Syft.☆165Updated last week
- Generate SBOMs with gh CLI☆165Updated last month
- Go library for Sigstore signing and verification☆47Updated last week
- An Action for printing OIDC claims in GitHub Actions.☆76Updated 3 months ago
- Lock Action to support deployment locking for the branch-deploy Action☆31Updated last week
- ☆45Updated last year
- SARIF Microsoft Visual Studio Code extension☆111Updated 3 weeks ago
- Find stale repositories in a GitHub organization.☆139Updated last week
- GitHub token permissions Monitor and Advisor actions☆257Updated 4 months ago
- GitHub Action to enable automated security updates and open a issue/PR in repos in an org that have dependency files but no dependabot.ya…☆184Updated last week
- Find license compliance and security issues in your applications with FOSSA and GitHub Actions.☆46Updated 3 weeks ago
- JavaScript implementation of The Update Framework (TUF)☆73Updated last week
- A GitHub Action to run the markdownlint-cli2 tool for linting Markdown/CommonMark files with the markdownlint library☆93Updated this week
- GitHub Action composite to dump context☆39Updated 3 months ago
- Demo repository showcasing how to use reusable workflows to build artifact attestations☆8Updated this week