The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
☆244May 26, 2025Updated last year
Alternatives and similar repositories for s2c2f
Users that are interested in s2c2f are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Open Source Software Secure Supply Chain Framework☆238Oct 28, 2022Updated 3 years ago
- OpenVEX Specification☆192Sep 9, 2026Updated last month
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆547Updated this week
- in-toto Attestation Framework☆382Oct 2, 2026Updated last week
- Supply-chain Levels for Software Artifacts☆1,940Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A place to systematically store software bill of materials (SBOM) documents.☆51Jun 1, 2023Updated 3 years ago
- Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.☆92Oct 3, 2026Updated last week
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,553Updated this week
- Format agnostic SBOM tooling☆156Nov 20, 2025Updated 10 months ago
- Umbrella Repository Service for TUF☆68Updated this week
- ☆87Sep 23, 2026Updated 2 weeks ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆117Updated this week
- in-toto is a framework to protect supply chain integrity.☆1,050Aug 27, 2026Updated last month
- Open Source Maturity Model☆17Apr 30, 2024Updated 2 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ☆260Sep 28, 2026Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- ☆25Nov 8, 2024Updated last year
- Machine-readable specification for the attestation of security-relevant data.☆81Updated this week
- Website and API for OpenSSF Scorecard☆33Oct 1, 2026Updated last week
- A specification for signing methods and formats used by Secure Systems Lab projects.☆112Updated this week
- A utility to generate SPDX-compliant Bill of Materials manifests☆472Updated this week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆122Feb 28, 2026Updated 7 months ago
- ☆101Sep 27, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆166Updated this week
- ☆34Updated this week
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆210Oct 2, 2026Updated last week
- Collection of tools for analyzing open source packages.☆371Jul 31, 2026Updated 2 months ago
- OpenSSF Working Group on Securing Software Repositories☆134Apr 6, 2026Updated 6 months ago
- Verify provenance from SLSA compliant builders☆346Aug 7, 2026Updated 2 months ago
- Enrich SBOMs with data from third party services☆240Sep 21, 2026Updated 2 weeks ago
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,076Updated this week
- sbomasm: The Complete SBOM Management Toolkit☆131Sep 21, 2026Updated 2 weeks ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more☆583Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,745Updated this week
- vexctl is a tool to attest VEX impact statements☆45Mar 27, 2023Updated 3 years ago
- sigstore the hard way!☆121May 29, 2026Updated 4 months ago
- Reference GitHub Workflows for SBOM generation from the CISA SBOM Generation Reference Implementation Tiger Team☆34Feb 2, 2026Updated 8 months ago
- 🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!☆2,264Dec 8, 2025Updated 10 months ago
- nginx image demo☆19Sep 11, 2023Updated 3 years ago