microsoft / sarif-js-sdkLinks
JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oasis-tcs/sarif-spec)
☆30Updated last year
Alternatives and similar repositories for sarif-js-sdk
Users that are interested in sarif-js-sdk are comparing it to the libraries listed below
Sorting:
- JS/TS library to easily build valid SARIF output from your javascript based SAST tools☆17Updated this week
- ESLint Plugin focused on common security issues and misconfigurations.☆48Updated 9 months ago
- GitHub Action to combine multiple PRs into a single one☆139Updated 8 months ago
- Collection of security best practices for package managers.☆164Updated 3 years ago
- reference implementation of conventionalcommits.org spec☆51Updated 6 months ago
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆98Updated 3 weeks ago
- Find license compliance and security issues in your applications with FOSSA and GitHub Actions.☆61Updated this week
- JavaScript implementation of The Update Framework (TUF)☆82Updated 2 weeks ago
- SARIF Microsoft Visual Studio Code extension☆123Updated last week
- ☆140Updated 2 weeks ago
- Lock Action to support deployment locking for the branch-deploy Action☆50Updated last week
- OASIS SARIF TC: Repository for development of the draft standard, where requests for modification should be made via Github Issues☆188Updated 2 weeks ago
- A developer-friendly secrets detection tool for CI and pre-commit hooks based on Yelp's detect-secrets☆52Updated 3 years ago
- CLI to run a octoherd scripts on one or multiple repositories☆102Updated this week
- GitHub Action to enable automated security updates and open a issue/PR in repos in an org that have dependency files but no dependabot.ya…☆216Updated last week
- Octokit plugin for GitHub’s recommended request throttling☆123Updated this week
- 🛠️ Get/set persisted configuration using YAML/JSON files in repositories☆41Updated 2 weeks ago
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆135Updated last week
- Bump.sh CLI - Deploy your OpenAPI & AsyncAPI documentations from your CI☆62Updated this week
- Find stale repositories in a GitHub organization.☆190Updated this week
- Code-signing for npm packages☆172Updated this week
- ☆55Updated last week
- Official GitHub Action for OpenSSF Scorecard.☆339Updated last week
- GitHub Action to expose GitHub runtime to the workflow☆83Updated last week
- ☆16Updated 9 months ago
- ✔️ A command-line JSON, YAML and TOML validator that's on your wavelength☆38Updated this week
- Orchestrate GitHub Actions Security☆301Updated this week
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆111Updated 3 months ago
- A JS library powered by the 1Password CLI☆106Updated last month
- An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.☆55Updated last week