☆157Jul 15, 2026Updated this week
Alternatives and similar repositories for security-baseline
Users that are interested in security-baseline are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Privateer plugin for scanning the security hygiene of a GitHub repository.☆28Updated this week
- Privateer is a plugin-based framework for security & compliance evaluations.☆22Updated this week
- Machine-readable specification for the attestation of security-relevant data.☆80Updated this week
- Format agnostic SBOM tooling☆155Nov 20, 2025Updated 8 months ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆48Jun 23, 2026Updated 3 weeks ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Global Cyber Policy Working Group☆119Updated this week
- Minimizing rework for governance activities.☆59Updated this week
- Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.☆89Jul 6, 2026Updated 2 weeks ago
- Using AI Agents for Audit SBOMs for OSS Compliance☆15Apr 7, 2025Updated last year
- TACOS framework structural details☆20May 12, 2025Updated last year
- Log monitor for Rekor to verify immutability and monitor entries☆56Updated this week
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆179May 1, 2026Updated 2 months ago
- Website and API for OpenSSF Scorecard☆29Jul 13, 2026Updated last week
- Interfaces and implementations for building Kubernetes releases.☆20Updated this week
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Technical Advisory Council☆148Jul 14, 2026Updated last week
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆151Jul 10, 2026Updated last week
- A TUF repository and signing tool☆48Jul 13, 2026Updated last week
- Vuln Disclosure WG's new SIG☆11Jan 2, 2024Updated 2 years ago
- sbomasm: The Complete SBOM Management Toolkit☆121Jul 14, 2026Updated last week
- Go module to generate and transform VEX documents☆69Updated this week
- ☆87Dec 10, 2025Updated 7 months ago
- SBOM Search - Context aware search in SBOM repositories☆32Nov 24, 2025Updated 7 months ago
- A tool to create, transform and attest VEX metadata☆204Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A proof-of-concept for how the SLSA Source Track could be implemented.☆18Updated this week
- OpenSSF Working Group on Securing Software Repositories☆129Apr 6, 2026Updated 3 months ago
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆238May 26, 2025Updated last year
- Tool for visualizing the Open SSF Scorecard Api data in a human friendly way☆19Updated this week
- 🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)☆53Updated this week
- ☆24Jul 13, 2026Updated last week
- ☆166Updated this week
- Automating Compliance Tooling Project☆24Jan 28, 2022Updated 4 years ago
- The model for the information captured in SPDX version 3 standard.☆102Updated this week
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Generate a score for your sbom to understand if it will actually be useful.☆241Aug 13, 2024Updated last year
- Model Signing Specification☆21May 15, 2026Updated 2 months ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆116Updated this week
- Insights into the world's most critical open source software.☆250Updated this week
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆573Updated this week
- Everything you ever wanted to know about the CRA and its implementation☆170Mar 31, 2026Updated 3 months ago
- ☆22Jul 16, 2025Updated last year