ossf / package-manager-best-practices
Collection of security best practices for package managers.
☆162Updated 2 years ago
Alternatives and similar repositories for package-manager-best-practices:
Users that are interested in package-manager-best-practices are comparing it to the libraries listed below
- Find security vulnerabilities in open source npm packages while you code☆205Updated 2 years ago
- ESLint plugin to detect and stop Trojan Source attacks☆76Updated 2 years ago
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆119Updated last month
- ☆132Updated this week
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆27Updated 9 months ago
- ESLint Plugin focused on common security issues and misconfigurations.☆40Updated 3 weeks ago
- Programmatically fetch security vulnerabilities with one or many strategies (NPM Audit, Sonatype, Snyk, Node.js DB).☆30Updated last week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆33Updated 3 weeks ago
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆126Updated last month
- Orchestrate GitHub Actions Security☆276Updated last month
- ☆58Updated last year
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆179Updated last year
- Do you have a boatload of speaking gigs? Use this CLI to manage them all!☆35Updated 2 years ago
- Code-signing for npm packages☆161Updated this week
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆186Updated 2 weeks ago
- Detect trojan source attacks that employ unicode bidi attacks to inject malicious code☆47Updated 2 years ago
- Security & License Compliance For Your App's Dependencies 🪱☆471Updated 6 months ago
- OpenSSF Security Tooling Working Group☆307Updated 9 months ago
- A developer-friendly secrets detection tool for CI and pre-commit hooks based on Yelp's detect-secrets☆50Updated 2 years ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆80Updated this week
- Open Source Software Secure Supply Chain Framework☆235Updated 2 years ago
- A documentation and tracking project with the goal of making package management systems more secure.☆50Updated 4 years ago
- OWASP Foundation Web Respository☆72Updated 2 months ago
- ☆49Updated this week
- GitHub token permissions Monitor and Advisor actions☆275Updated 2 weeks ago
- Security advisories for Node.js and the JavaScript ecosystem.☆41Updated 3 years ago
- GitHub action to generate a CycloneDX SBOM for Node.js☆21Updated 2 months ago
- A CLI tool to find out if your dependencies support a given version of node.☆104Updated last year
- Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)☆191Updated last week
- easy webperf trace sharing☆123Updated this week