The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
☆238May 26, 2025Updated last year
Alternatives and similar repositories for s2c2f
Users that are interested in s2c2f are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Open Source Software Secure Supply Chain Framework☆238Oct 28, 2022Updated 3 years ago
- OpenVEX Specification☆187Jan 16, 2026Updated 6 months ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆537Updated this week
- in-toto Attestation Framework☆354Updated this week
- Supply-chain Levels for Software Artifacts☆1,891Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A place to systematically store software bill of materials (SBOM) documents.☆51Jun 1, 2023Updated 3 years ago
- Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.☆89Jul 6, 2026Updated 2 weeks ago
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,518Updated this week
- Format agnostic SBOM tooling☆155Nov 20, 2025Updated 8 months ago
- Umbrella Repository Service for TUF☆67Jul 9, 2026Updated last week
- ☆87Dec 10, 2025Updated 7 months ago
- in-toto is a framework to protect supply chain integrity.☆1,019Jul 13, 2026Updated last week
- Open Source Maturity Model☆17Apr 30, 2024Updated 2 years ago
- ☆260Jul 13, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A standard API specification for exchanging supply chain artifacts and intelligence☆110May 20, 2026Updated 2 months ago
- A specification for signing methods and formats used by Secure Systems Lab projects.☆106Jul 9, 2026Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆241Aug 13, 2024Updated last year
- ☆25Nov 8, 2024Updated last year
- Machine-readable specification for the attestation of security-relevant data.☆80Updated this week
- Website and API for OpenSSF Scorecard☆29Jul 13, 2026Updated last week
- A utility to generate SPDX-compliant Bill of Materials manifests☆461Updated this week
- Enrich SBOMs with data from third party services☆231May 18, 2026Updated 2 months ago
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆208Updated this week
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆120Feb 28, 2026Updated 4 months ago
- ☆101Sep 27, 2024Updated last year
- ☆157Updated this week
- ☆31Jul 13, 2026Updated last week
- Collection of tools for analyzing open source packages.☆367Jun 15, 2026Updated last month
- OpenSSF Working Group on Securing Software Repositories☆129Apr 6, 2026Updated 3 months ago
- Verify provenance from SLSA compliant builders☆338Mar 9, 2026Updated 4 months ago
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,048Jul 13, 2026Updated last week
- sbomasm: The Complete SBOM Management Toolkit☆121Jul 14, 2026Updated last week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more☆570Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,589Updated this week
- vexctl is a tool to attest VEX impact statements☆45Mar 27, 2023Updated 3 years ago
- sigstore the hard way!☆120May 29, 2026Updated last month
- Reference GitHub Workflows for SBOM generation from the CISA SBOM Generation Reference Implementation Tiger Team☆34Feb 2, 2026Updated 5 months ago
- 🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!☆2,266Dec 8, 2025Updated 7 months ago
- nginx image demo☆19Sep 11, 2023Updated 2 years ago