ossf / gemaraLinks
Minimizing rework for governance activities.
☆25Updated this week
Alternatives and similar repositories for gemara
Users that are interested in gemara are comparing it to the libraries listed below
Sorting:
- An opinionated tooling platform for managing compliance as code, using continuous integration and NIST's OSCAL standard.☆208Updated this week
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆189Updated last year
- The Compliance Validator☆184Updated last month
- Technical Advisory Council☆131Updated this week
- ☆250Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆234Updated last year
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆177Updated 10 months ago
- Repository for on-going work as part of the SBOM for AI Tiger Team effort.☆39Updated 2 months ago
- A list of tools, blog posts, and other resources that further the use and adoption of OSCAL standards.☆183Updated 3 months ago
- This repo is a consolidation of Secure Software Supply Chain resources, such as talks, whitepapers, conferences and more.☆139Updated 3 years ago
- OpenVEX Specification☆160Updated 4 months ago
- Documenting your Threat Models with HCL☆433Updated this week
- Machine-readable specification for the attestation of security-relevant data.☆63Updated last month
- A repository containing OSCAL serializations of the CIS Critical Security Controls☆55Updated 6 months ago
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆113Updated last week
- Enrich SBOMs with data from third party services☆196Updated last month
- ☆16Updated last year
- A standard API specification for exchanging supply chain artifacts and intelligence☆87Updated 2 weeks ago
- FedRAMP Automation☆344Updated 6 months ago
- A tool to check the security settings of Github Organizations.☆72Updated 2 years ago
- A tool to create, transform and attest VEX metadata☆160Updated this week
- ☆123Updated this week
- ☆67Updated last year
- Segment's Threat Modeling training for our engineers☆245Updated 4 years ago
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆215Updated 4 months ago
- ☆102Updated last year
- Privateer is a plugin-based framework to validate the status of deployed resources.☆16Updated this week
- The purpose of the Metrics & Metadata (formerly Identifying Security Threats) working group is to enable stakeholders to have informed co…☆223Updated last year
- Open Security Controls Assessment Language (OSCAL)☆788Updated last week
- A reading list for software supply-chain security.☆365Updated 2 years ago