The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
☆244May 26, 2025Updated last year
Alternatives and similar repositories for s2c2f
Users that are interested in s2c2f are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Open Source Software Secure Supply Chain Framework☆238Oct 28, 2022Updated 3 years ago
- OpenVEX Specification☆191Sep 9, 2026Updated last week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆546Updated this week
- in-toto Attestation Framework☆373Updated this week
- Supply-chain Levels for Software Artifacts☆1,928Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A place to systematically store software bill of materials (SBOM) documents.☆51Jun 1, 2023Updated 3 years ago
- Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.☆91Sep 7, 2026Updated last week
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,541Updated this week
- Format agnostic SBOM tooling☆156Nov 20, 2025Updated 10 months ago
- Umbrella Repository Service for TUF☆68Updated this week
- ☆87Aug 19, 2026Updated last month
- A standard API specification for exchanging supply chain artifacts and intelligence☆116Updated this week
- in-toto is a framework to protect supply chain integrity.☆1,040Aug 27, 2026Updated 3 weeks ago
- Open Source Maturity Model☆17Apr 30, 2024Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆260Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- ☆25Nov 8, 2024Updated last year
- Machine-readable specification for the attestation of security-relevant data.☆80Sep 12, 2026Updated last week
- Website and API for OpenSSF Scorecard☆33Updated this week
- A specification for signing methods and formats used by Secure Systems Lab projects.☆111Jul 23, 2026Updated last month
- A utility to generate SPDX-compliant Bill of Materials manifests☆466Updated this week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆121Feb 28, 2026Updated 6 months ago
- ☆101Sep 27, 2024Updated last year
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- ☆166Updated this week
- ☆33Updated this week
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆210Updated this week
- Collection of tools for analyzing open source packages.☆371Jul 31, 2026Updated last month
- OpenSSF Working Group on Securing Software Repositories☆134Apr 6, 2026Updated 5 months ago
- Verify provenance from SLSA compliant builders☆345Aug 7, 2026Updated last month
- Enrich SBOMs with data from third party services☆240Aug 28, 2026Updated 3 weeks ago
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,067Updated this week
- sbomasm: The Complete SBOM Management Toolkit☆129Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more☆582Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,697Updated this week
- vexctl is a tool to attest VEX impact statements☆45Mar 27, 2023Updated 3 years ago
- sigstore the hard way!☆121May 29, 2026Updated 3 months ago
- Reference GitHub Workflows for SBOM generation from the CISA SBOM Generation Reference Implementation Tiger Team☆34Feb 2, 2026Updated 7 months ago
- 🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!☆2,263Dec 8, 2025Updated 9 months ago
- nginx image demo☆19Sep 11, 2023Updated 3 years ago