The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
☆242May 26, 2025Updated last year
Alternatives and similar repositories for s2c2f
Users that are interested in s2c2f are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Open Source Software Secure Supply Chain Framework☆238Oct 28, 2022Updated 3 years ago
- OpenVEX Specification☆190Jan 16, 2026Updated 7 months ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆546Aug 24, 2026Updated last week
- in-toto Attestation Framework☆369Updated this week
- Supply-chain Levels for Software Artifacts☆1,919Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A place to systematically store software bill of materials (SBOM) documents.☆51Jun 1, 2023Updated 3 years ago
- Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.☆91Updated this week
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,536Updated this week
- Format agnostic SBOM tooling☆156Nov 20, 2025Updated 9 months ago
- Umbrella Repository Service for TUF☆68Aug 14, 2026Updated 2 weeks ago
- ☆87Aug 19, 2026Updated last week
- A standard API specification for exchanging supply chain artifacts and intelligence☆113Aug 12, 2026Updated 2 weeks ago
- in-toto is a framework to protect supply chain integrity.☆1,035Updated this week
- Open Source Maturity Model☆17Apr 30, 2024Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ☆260Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- ☆25Nov 8, 2024Updated last year
- Machine-readable specification for the attestation of security-relevant data.☆81Updated this week
- Website and API for OpenSSF Scorecard☆31Updated this week
- A specification for signing methods and formats used by Secure Systems Lab projects.☆110Jul 23, 2026Updated last month
- A utility to generate SPDX-compliant Bill of Materials manifests☆466Updated this week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆121Feb 28, 2026Updated 6 months ago
- ☆101Sep 27, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆162Updated this week
- ☆33Updated this week
- Collection of tools for analyzing open source packages.☆370Jul 31, 2026Updated 3 weeks ago
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆210Updated this week
- OpenSSF Working Group on Securing Software Repositories☆134Apr 6, 2026Updated 4 months ago
- Verify provenance from SLSA compliant builders☆343Aug 7, 2026Updated 3 weeks ago
- Enrich SBOMs with data from third party services☆235Updated this week
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,065Updated this week
- sbomasm: The Complete SBOM Management Toolkit☆128Updated this week
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more☆583Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,660Aug 24, 2026Updated last week
- vexctl is a tool to attest VEX impact statements☆45Mar 27, 2023Updated 3 years ago
- sigstore the hard way!☆120May 29, 2026Updated 3 months ago
- Reference GitHub Workflows for SBOM generation from the CISA SBOM Generation Reference Implementation Tiger Team☆34Feb 2, 2026Updated 6 months ago
- 🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!☆2,263Dec 8, 2025Updated 8 months ago
- nginx image demo☆19Sep 11, 2023Updated 2 years ago