oss-review-toolkit / ort-ci-github-action
Run ORT in your GitHub action workflow to do licensing, security and best practices checks and generate reports/SBOMs
☆30Updated last month
Alternatives and similar repositories for ort-ci-github-action:
Users that are interested in ort-ci-github-action are comparing it to the libraries listed below
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆34Updated 2 months ago
- Generates SPDX bill-of-material files from a package input and license scan☆13Updated last year
- Enrich SBOMs with data from third party services☆168Updated 3 weeks ago
- Official GitHub Action for OpenSSF Scorecard.☆293Updated this week
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆69Updated this week
- GitHub app for SBOM creation using cdxgen and upload to Dependency-Track☆18Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆229Updated 8 months ago
- GitHub Action for creating software bill of materials using Syft.☆180Updated 3 weeks ago
- Generate SBOMs with gh CLI☆180Updated 7 months ago
- SPDX Merge tool☆43Updated this week
- GitHub Action to enable automated security updates and open a issue/PR in repos in an org that have dependency files but no dependabot.ya…☆199Updated last week
- GitHub Action for submitting Maven dependencies☆50Updated 2 weeks ago
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆131Updated last week
- A light-weight app to audit and inventory large codebases for open source license compliance.☆65Updated this week
- Generate docs for GitHub actions☆92Updated last week
- Generate CycloneDX Software Bill of Materials (SBOM) from webpack bundles at compile time.☆26Updated this week
- Submit SBOMs to GitHub's dependency submission API☆12Updated 2 years ago
- Publishes BOMs to Dependency-Track from GitHub Actions☆53Updated 6 months ago
- Probot & GitHub Action example☆34Updated last week
- GitHub token permissions Monitor and Advisor actions☆284Updated 2 weeks ago
- Synchronize GitHub Code Scanning alerts to Jira issues☆85Updated 3 weeks ago
- A java api and command line tool for scanning, reporting and fixing a git repository's InnerSource Readiness based on a supplied specific…☆20Updated last year
- GitHub Action to get a license overview in SPDX format☆14Updated 3 years ago
- Docker Scout GitHub Action☆109Updated last week
- Website and API for OpenSSF Scorecard☆24Updated last week
- SBOM quality score - Quality metrics for your sboms☆206Updated this week
- GitHub Advanced Security Policy as Code☆82Updated last week
- This project creates a repos.json that can be utilized by the SAP InnerSource Portal.☆32Updated 3 weeks ago
- OSPO Landscape☆36Updated this week
- GitHub Action that given an organization or repository, produces information about the contributors over the specified time period.☆119Updated last week