A community collection of security reviews of open source software components.
☆101Feb 29, 2024Updated 2 years ago
Alternatives and similar repositories for security-reviews
Users that are interested in security-reviews are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Mar 13, 2024Updated 2 years ago
- Machine-readable specification for the attestation of security-relevant data.☆81Updated this week
- The purpose of the Metrics & Metadata (formerly Identifying Security Threats) working group is to enable stakeholders to have informed co…☆222Apr 23, 2024Updated 2 years ago
- Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.☆138Updated this week
- ☆23Oct 26, 2021Updated 4 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆207Jan 15, 2026Updated 7 months ago
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆224Feb 4, 2026Updated 6 months ago
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,065Updated this week
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆141Aug 19, 2026Updated last week
- Supply Chain Query Tool☆13May 25, 2022Updated 4 years ago
- Helping allocate resources to secure the critical open source projects we all depend on.☆410May 8, 2025Updated last year
- A TUF repository and signing tool☆50Updated this week
- Given a buildinfo file from a Debian package, generate instructions for attempting to reproduce the binary packages built from the associ…☆17Sep 24, 2022Updated 3 years ago
- OpenSSF Security Tooling Working Group☆326Jul 6, 2025Updated last year
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆35Apr 4, 2023Updated 3 years ago
- Simple and pratical security gate for Github Security Alerts☆22Aug 25, 2026Updated last week
- Solidity bootcamp☆14Jan 27, 2022Updated 4 years ago
- A bot that watches a website or GitHub assets for changes and communicates them to Slack.☆11Apr 5, 2019Updated 7 years ago
- Supply Chain Integrity Model☆108Jun 12, 2023Updated 3 years ago
- Go implementation of The Update Framework heavily influenced by python-tuf☆14Mar 7, 2024Updated 2 years ago
- in-toto Enhancements☆20Feb 17, 2025Updated last year
- SLSA level 3 action☆12Apr 26, 2024Updated 2 years ago
- Privateer is a plugin-based framework for security & compliance evaluations.☆25Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Collection of tools for analyzing open source packages.☆370Jul 31, 2026Updated last month
- Cryptographic and general-purpose routines for Golang Secure Systems Lab projects at NYU☆30Aug 20, 2026Updated last week
- Open Source Vulnerability schema.☆269Updated this week
- Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.☆21Jul 16, 2026Updated last month
- The Great Multi-Factor Authentication (MFA) Distribution Project of the Open Source Security Foundation (OpenSSF). We work to distribute …☆54Dec 28, 2021Updated 4 years ago
- Kubernetes Security Testing Guide☆27Apr 22, 2024Updated 2 years ago
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Jul 5, 2023Updated 3 years ago
- Application Security Workflow Automation using Docker and Kubernetes☆23Dec 11, 2022Updated 3 years ago
- OASIS TC Open Repository: A GitHub repository for management of non-normative information about the work of the CSAF Technical Committee,…☆22Jul 28, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)☆205Aug 21, 2026Updated last week
- standard for Uptane☆44Jul 24, 2026Updated last month
- threatspec - continuous threat modeling, through code☆391Dec 30, 2020Updated 5 years ago
- A straightforward tool for exploiting SMTP Smuggling vulnerabilities.☆14Jul 22, 2024Updated 2 years ago
- Sigstore's Protocol Buffer specifications☆36Aug 21, 2026Updated last week
- ☆17Jan 3, 2021Updated 5 years ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆19Aug 3, 2026Updated 3 weeks ago