ossf / s2c2fLinks
The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
☆219Updated 6 months ago
Alternatives and similar repositories for s2c2f
Users that are interested in s2c2f are comparing it to the libraries listed below
Sorting:
- Generate a score for your sbom to understand if it will actually be useful.☆234Updated last year
- A standard API specification for exchanging supply chain artifacts and intelligence☆91Updated last month
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆194Updated last year
- OpenVEX Specification☆162Updated 5 months ago
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆210Updated last month
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆255Updated this week
- ☆252Updated this week
- Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.☆74Updated last week
- Enrich SBOMs with data from third party services☆201Updated 3 months ago
- A tool to create, transform and attest VEX metadata☆166Updated last week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆111Updated 2 weeks ago
- A reading list for software supply-chain security.☆366Updated 3 years ago
- ☆68Updated last year
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆204Updated 2 months ago
- Utility that provides an API platform for validating, querying and managing BOM data☆122Updated 2 months ago
- Format agnostic SBOM tooling☆122Updated last week
- ☆102Updated last year
- Open Source Software Secure Supply Chain Framework☆238Updated 3 years ago
- Machine-readable specification for the attestation of security-relevant data.☆66Updated 2 months ago
- in-toto Attestation Framework☆310Updated last week
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆446Updated this week
- Support CI generation of SBOMs via golang tooling.☆423Updated 10 months ago
- A universal SBOM representation in protocol buffers☆308Updated last week
- ☆119Updated this week
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆338Updated 2 years ago
- Technical Advisory Council☆133Updated 2 weeks ago
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆125Updated last month
- Software Component Verification Standard (SCVS)☆150Updated 8 months ago
- A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles☆546Updated 6 months ago
- sbomasm: The Complete SBOM Management Toolkit☆94Updated last week