ossf / s2c2f
The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
☆202Updated last month
Alternatives and similar repositories for s2c2f:
Users that are interested in s2c2f are comparing it to the libraries listed below
- A standard API specification for exchanging supply chain artifacts and intelligence☆74Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆226Updated 7 months ago
- OpenVEX Specification☆143Updated 8 months ago
- Enrich SBOMs with data from third party services☆161Updated last month
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆180Updated last year
- ☆232Updated this week
- Format agnostic SBOM tooling☆102Updated this week
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆193Updated 3 months ago
- A reading list for software supply-chain security.☆362Updated 2 years ago
- SBOM quality score - Quality metrics for your sboms☆196Updated this week
- Visualizer for GUAC☆28Updated last week
- A BOM repository server for distributing CycloneDX BOMs☆75Updated last year
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆186Updated 3 weeks ago
- Potential WG on Artificial Intelligence and Machine Learning (AI/ML)☆69Updated 5 months ago
- ☆60Updated 8 months ago
- A tool to create, transform and attest VEX metadata☆132Updated this week
- in-toto Attestation Framework☆261Updated last week
- Check SPDX SBOM for NTIA minimum elements☆60Updated last week
- Utility that provides an API platform for validating, querying and managing BOM data☆104Updated 4 months ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆171Updated 4 months ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆86Updated last week
- Technical Advisory Council☆118Updated this week
- ☆100Updated 5 months ago
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Updated last year
- Software Component Verification Standard (SCVS)☆141Updated 11 months ago
- Machine-readable specification for the attestation of security-relevant data.☆57Updated last week
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆88Updated this week
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆63Updated this week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year