ossf / s2c2fLinks
The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
☆215Updated 5 months ago
Alternatives and similar repositories for s2c2f
Users that are interested in s2c2f are comparing it to the libraries listed below
Sorting:
- Generate a score for your sbom to understand if it will actually be useful.☆234Updated last year
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆191Updated last year
- OpenVEX Specification☆161Updated 5 months ago
- Check SPDX SBOM for NTIA minimum elements☆73Updated last week
- A standard API specification for exchanging supply chain artifacts and intelligence☆90Updated last week
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆207Updated 3 weeks ago
- ☆251Updated last week
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆246Updated 2 weeks ago
- ☆67Updated last year
- A reading list for software supply-chain security.☆365Updated 2 years ago
- Enrich SBOMs with data from third party services☆197Updated 2 months ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆105Updated 3 weeks ago
- Machine-readable specification for the attestation of security-relevant data.☆63Updated last month
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆334Updated 2 years ago
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆203Updated last month
- A tool to create, transform and attest VEX metadata☆164Updated 2 weeks ago
- ☆102Updated last year
- Format agnostic SBOM tooling☆119Updated 3 weeks ago
- in-toto Attestation Framework☆305Updated 3 weeks ago
- Utility that provides an API platform for validating, querying and managing BOM data☆123Updated last month
- Visualizer for GUAC☆28Updated 2 months ago
- A universal SBOM representation in protocol buffers☆306Updated 3 weeks ago
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆439Updated this week
- Utility that provides an API and CLI to identify licenses and legal terms☆53Updated 4 months ago
- Open Source Software Secure Supply Chain Framework☆236Updated 3 years ago
- ☆115Updated this week
- A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles☆543Updated 5 months ago
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆117Updated 3 weeks ago
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆176Updated this week
- Technical Advisory Council☆132Updated last week