ossf / s2c2fLinks
The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
☆225Updated 8 months ago
Alternatives and similar repositories for s2c2f
Users that are interested in s2c2f are comparing it to the libraries listed below
Sorting:
- A standard API specification for exchanging supply chain artifacts and intelligence☆98Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆237Updated last year
- OpenVEX Specification☆166Updated 3 weeks ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆195Updated 3 weeks ago
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆215Updated 3 months ago
- ☆255Updated last week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆110Updated 2 weeks ago
- Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.☆79Updated last week
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆267Updated this week
- A tool to create, transform and attest VEX metadata☆172Updated this week
- Enrich SBOMs with data from third party services☆214Updated this week
- A reading list for software supply-chain security.☆366Updated 3 years ago
- ☆74Updated last month
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆210Updated this week
- Utility that provides an API platform for validating, querying and managing BOM data☆124Updated last month
- A universal SBOM representation in protocol buffers☆315Updated last week
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆344Updated 2 years ago
- ☆102Updated last year
- Technical Advisory Council☆134Updated last week
- Format agnostic SBOM tooling☆131Updated 2 months ago
- Machine-readable specification for the attestation of security-relevant data.☆72Updated last week
- in-toto Attestation Framework☆323Updated this week
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆478Updated this week
- Open Source Software Secure Supply Chain Framework☆239Updated 3 years ago
- CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.☆452Updated last month
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆186Updated this week
- ☆16Updated last year
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆141Updated last month
- Visualizer for GUAC☆29Updated this week
- Securing Alice's, Bob's and Carl's software supply chain using in-toto☆104Updated last week