google / osv-scanner-action
☆29Updated this week
Alternatives and similar repositories for osv-scanner-action:
Users that are interested in osv-scanner-action are comparing it to the libraries listed below
- Official GitHub Action for OpenSSF Scorecard.☆294Updated last week
- Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded☆63Updated last week
- Purpose-built security agent for hosted runners☆34Updated this week
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆133Updated last week
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆82Updated 5 months ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆34Updated 2 months ago
- Orchestrate GitHub Actions Security☆284Updated last week
- Format agnostic SBOM tooling☆105Updated this week
- Generate SBOMs with gh CLI☆182Updated last week
- GitHub Action that given an organization or repository, produces information about the contributors over the specified time period.☆120Updated last week
- Log monitor for Rekor to verify immutability and monitor entries☆31Updated last week
- Publish a signed build provenance from your GitHub Actions workflow☆63Updated 11 months ago
- An SBOM query language and associated utilities☆54Updated last year
- Runtime Security Solution for your CI/CD Pipeline☆101Updated last month
- Protect GitHub Actions with Tracee☆81Updated 2 months ago
- Open Source Vulnerability schema.☆198Updated this week
- Verify provenance from SLSA compliant builders☆257Updated 3 weeks ago
- Find stale repositories in a GitHub organization.☆179Updated last week
- Action for generating attestations for workflow artifacts☆49Updated last week
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆189Updated this week
- ☆42Updated 6 months ago
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆69Updated this week
- Go library for Sigstore signing and verification☆62Updated last week
- The model for the information captured in SPDX version 3 standard.☆82Updated this week
- GitHub Action to enable automated security updates and open a issue/PR in repos in an org that have dependency files but no dependabot.ya…☆199Updated last week
- Throw a tag at it and it comes back with a checksum.☆120Updated this week
- GitHub CLI extension for working with CodeQL☆32Updated 2 months ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆88Updated this week
- An Action for printing OIDC claims in GitHub Actions.☆92Updated last month
- GitHub Advanced Security Policy as Code☆82Updated last week