ossf / s2c2fLinks
The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
☆212Updated 3 months ago
Alternatives and similar repositories for s2c2f
Users that are interested in s2c2f are comparing it to the libraries listed below
Sorting:
- Check SPDX SBOM for NTIA minimum elements☆67Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆233Updated last year
- A standard API specification for exchanging supply chain artifacts and intelligence☆84Updated 2 months ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆189Updated last year
- OpenVEX Specification☆156Updated 3 months ago
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆197Updated last week
- ☆245Updated this week
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆201Updated 4 months ago
- A reading list for software supply-chain security.☆364Updated 2 years ago
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆235Updated this week
- ☆101Updated 11 months ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆101Updated last month
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆423Updated this week
- Utility that provides an API platform for validating, querying and managing BOM data☆119Updated 3 weeks ago
- ☆65Updated last year
- Technical Advisory Council☆129Updated last week
- Enrich SBOMs with data from third party services☆190Updated 2 weeks ago
- Machine-readable specification for the attestation of security-relevant data.☆61Updated last month
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆329Updated 2 years ago
- A tool to create, transform and attest VEX metadata☆153Updated this week
- ☆107Updated this week
- Visualizer for GUAC☆28Updated last week
- Format agnostic SBOM tooling☆115Updated 3 weeks ago
- A universal SBOM representation in protocol buffers☆299Updated last week
- Utility that provides an API and CLI to identify licenses and legal terms☆52Updated 2 months ago
- sbomasm: The Complete SBOM Management Toolkit☆77Updated last week
- in-toto Attestation Framework☆297Updated this week
- CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.☆399Updated last week
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆108Updated 2 weeks ago
- Open Source Software Secure Supply Chain Framework☆236Updated 2 years ago