ossf / package-manager-best-practices
Collection of security best practices for package managers.
☆162Updated 2 years ago
Alternatives and similar repositories for package-manager-best-practices:
Users that are interested in package-manager-best-practices are comparing it to the libraries listed below
- Find security vulnerabilities in open source npm packages while you code☆205Updated 3 years ago
- ESLint plugin to detect and stop Trojan Source attacks☆76Updated 2 years ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆85Updated 2 weeks ago
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆120Updated 3 months ago
- ☆132Updated last month
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆127Updated 2 months ago
- GitHub token permissions Monitor and Advisor actions☆284Updated 2 weeks ago
- Orchestrate GitHub Actions Security☆282Updated last week
- proxy designed to reduce the attack surface of npm publish☆115Updated last month
- Do you have a boatload of speaking gigs? Use this CLI to manage them all!☆35Updated 2 years ago
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆236Updated 5 months ago
- Generate SBOMs with gh CLI☆180Updated 7 months ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆181Updated last year
- GitHub action to generate a CycloneDX SBOM for Node.js☆21Updated 3 months ago
- Official GitHub Action for OpenSSF Scorecard.☆293Updated this week
- ESLint Plugin focused on common security issues and misconfigurations.☆40Updated 2 months ago
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆27Updated 10 months ago
- Code-signing for npm packages☆161Updated last week
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆187Updated 3 weeks ago
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆131Updated last week
- Security advisories for Node.js and the JavaScript ecosystem.☆41Updated 3 years ago
- ☆241Updated 2 weeks ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆99Updated 2 years ago
- A React-based component for viewing SARIF files.☆94Updated 5 months ago
- JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.☆241Updated 3 weeks ago
- Generate a score for your sbom to understand if it will actually be useful.☆229Updated 8 months ago
- Easy auditing & sandboxing for your JavaScript dependencies 🪱☆253Updated 2 years ago
- Open Source Software Secure Supply Chain Framework☆236Updated 2 years ago
- SARIF Microsoft Visual Studio Code extension☆114Updated last week
- TSLint security rules☆70Updated 4 years ago