oss-review-toolkit / ort-ci-github-action
Run ORT in your GitHub action workflow to do licensing, security and best practices checks and generate reports/SBOMs
☆26Updated last month
Alternatives and similar repositories for ort-ci-github-action:
Users that are interested in ort-ci-github-action are comparing it to the libraries listed below
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆32Updated 6 months ago
- Orchestrate GitHub Actions Security☆265Updated this week
- Submit SBOMs to GitHub's dependency submission API☆12Updated last year
- Github Action implementation of SLSA Provenance Generation☆47Updated this week
- Generates SPDX bill-of-material files from a package input and license scan☆12Updated 9 months ago
- Enrich SBOMs with data from third party services☆151Updated last week
- GitHub Action for creating software bill of materials using Syft.☆175Updated 3 weeks ago
- Official GitHub Action for OpenSSF Scorecard.☆276Updated this week
- GitHub Action to enable automated security updates and open a issue/PR in repos in an org that have dependency files but no dependabot.ya…☆189Updated this week
- Search Rekor for entries☆30Updated this week
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆53Updated 2 months ago
- SPDX Merge tool☆39Updated 4 months ago
- Example of using Actions OIDC token to proxy into a private network☆91Updated this week
- ☆22Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆224Updated 5 months ago
- Generate docs for GitHub actions☆88Updated this week
- This tool compares two Software Bill of Materials (SBOMs) and reports the differences.☆29Updated 2 months ago
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆95Updated 9 months ago
- Action for generating SBOM attestations for workflow artifacts☆22Updated this week
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆120Updated this week
- An OIDC client to retrieve a GitHub API scoped token from within an Actions workflow☆28Updated 9 months ago
- Helm charts for sigstore project☆67Updated last week
- Generate SBOMs with gh CLI☆175Updated 3 months ago
- GitHub action for Hadolint, A Dockerfile linting tool☆208Updated 10 months ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆99Updated 2 years ago
- Synchronize GitHub Code Scanning alerts to Jira issues☆80Updated 3 months ago
- Find stale repositories in a GitHub organization.☆149Updated this week
- Verify provenance from SLSA compliant builders☆239Updated 2 weeks ago
- Unified Policy Engine☆47Updated this week
- Manage multiple repository updates all at once.☆140Updated last year