ossf / s2c2f
The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
☆197Updated 3 weeks ago
Alternatives and similar repositories for s2c2f:
Users that are interested in s2c2f are comparing it to the libraries listed below
- A standard API specification for exchanging supply chain artifacts and intelligence☆72Updated last week
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆178Updated last year
- Generate a score for your sbom to understand if it will actually be useful.☆225Updated 6 months ago
- Enrich SBOMs with data from third party services☆158Updated last week
- OpenVEX Specification☆141Updated 7 months ago
- ☆231Updated this week
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆183Updated this week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆78Updated last week
- ☆100Updated 4 months ago
- Check SPDX SBOM for NTIA minimum elements☆59Updated 2 weeks ago
- SBOM quality score - Quality metrics for your sboms☆193Updated this week
- Open Source Software Secure Supply Chain Framework☆234Updated 2 years ago
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆193Updated 2 months ago
- Format agnostic SBOM tooling☆99Updated this week
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆307Updated last year
- Utility that provides an API platform for validating, querying and managing BOM data☆102Updated 3 months ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- A reading list for software supply-chain security.☆361Updated 2 years ago
- Potential WG on Artificial Intelligence and Machine Learning (AI/ML)☆61Updated 3 months ago
- Technical Advisory Council☆116Updated this week
- Software Component Verification Standard (SCVS)☆140Updated 10 months ago
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Updated last year
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆289Updated this week
- A BOM repository server for distributing CycloneDX BOMs☆75Updated 11 months ago
- ☆60Updated 7 months ago
- Visualizer for GUAC☆28Updated 3 weeks ago
- Open Source Vulnerability schema.☆191Updated last week
- OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Is…☆56Updated last month
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆62Updated this week
- OpenSSF Security Tooling Working Group☆306Updated 9 months ago