oscal-compass / compliance-to-policy-goLinks
Compliance-to-Policy (C2P) provides the framework to bridge the gap between compliance and policy administration in Go.
☆23Updated last month
Alternatives and similar repositories for compliance-to-policy-go
Users that are interested in compliance-to-policy-go are comparing it to the libraries listed below
Sorting:
- A workflow automation tool for compliance content authoring☆20Updated this week
- The community area and documents about Code of Conduct.☆18Updated 4 years ago
- An opinionated tooling platform for managing compliance as code, using continuous integration and NIST's OSCAL standard.☆223Updated this week
- The Compliance Validator☆184Updated last month
- Minimizing rework for governance activities.☆34Updated this week
- ☆253Updated this week
- ☆27Updated 3 months ago
- ORBIT: Open Resources for Baselines, Interoperability, and Tooling☆20Updated last week
- An http proxy for reproducibility.☆19Updated 2 years ago
- RapiDAST enables simple, continuous and fully automated application security testing☆78Updated this week
- Conforma artifact verifier and policy checker☆38Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆103Updated this week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆511Updated last week
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆221Updated 7 months ago
- Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.☆75Updated this week
- General sigstore community repo☆44Updated last week
- A tool to create, transform and attest VEX metadata☆169Updated this week
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆70Updated last week
- Component Registry (Corgi) aggregates component data across Red Hat's supported products, managed services, and internal product pipeline…☆17Updated 11 months ago
- in-toto Enhancements☆18Updated 10 months ago
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Updated 2 years ago
- Umbrella Repository Service for TUF☆57Updated last week
- FedRAMP Automation☆348Updated 8 months ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆195Updated 3 weeks ago
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆258Updated last week
- OpenVEX Specification☆164Updated 6 months ago
- ☆102Updated last year
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆18Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆235Updated last year
- A license scanner for container images and filesystems.☆127Updated this week