Machine-readable specification for the attestation of security-relevant data.
☆81Sep 12, 2026Updated last week
Alternatives and similar repositories for security-insights
Users that are interested in security-insights are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Privateer plugin for scanning the security hygiene of a GitHub repository.☆31Updated this week
- ☆87Aug 19, 2026Updated last month
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆50Jul 25, 2026Updated last month
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆35Apr 4, 2023Updated 3 years ago
- Technical Advisory Council☆152Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Supply Chain Query Tool☆13May 25, 2022Updated 4 years ago
- A community collection of security reviews of open source software components.☆101Feb 29, 2024Updated 2 years ago
- ☆166Sep 14, 2026Updated last week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆121Feb 28, 2026Updated 6 months ago
- A functional type system for policy inspection, audit and enforcement.☆14Aug 17, 2023Updated 3 years ago
- ☆101Sep 27, 2024Updated last year
- A standard API specification for exchanging supply chain artifacts and intelligence☆116Updated this week
- Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.☆91Sep 7, 2026Updated 2 weeks ago
- A tool for measuring InnerSource collaboration in a repository☆20Updated this week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Command line interface for Kusari☆16Updated this week
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,067Updated this week
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆190May 1, 2026Updated 4 months ago
- Model Signing Specification☆28Updated this week
- ☆51Updated this week
- PURL to CPE Relationship mapping project.☆131Updated this week
- OpenVEX Specification☆191Sep 9, 2026Updated last week
- A place to systematically store software bill of materials (SBOM) documents.☆51Jun 1, 2023Updated 3 years ago
- ☆22Sep 14, 2026Updated last week
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- The model for the information captured in SPDX version 3 standard.☆105Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆116Updated this week
- Stakeholder-Specific Vulnerability Categorization☆194Updated this week
- Log monitor for Rekor to verify immutability and monitor entries☆57Sep 14, 2026Updated last week
- Automatically assess and score software repositories for supply chain risk.☆129Updated this week
- Continuous Compliance makes it possible to enforce company policy on repositories. Continuous Compliance will automatically check your re…☆22Nov 24, 2025Updated 9 months ago
- A modular MCP server providing AI-driven vulnerability management skills, including severity classification and automated insights.☆42Aug 30, 2026Updated 3 weeks ago
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,541Updated this week
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆229Feb 4, 2026Updated 7 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- GitHub Action that given an organization or repository, produces information about the contributors over the specified time period.☆157Updated this week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆546Updated this week
- SBOM Search - Context aware search in SBOM repositories☆32Sep 14, 2026Updated last week
- A tiny tool for embedding CoSWID tags in EFI binaries☆26Sep 4, 2026Updated 2 weeks ago
- Software Supply Chain Security Platform☆422Updated this week
- Format agnostic SBOM tooling☆156Nov 20, 2025Updated 10 months ago
- A universal SBOM representation in protocol buffers☆334Updated this week