A community collection of security reviews of open source software components.
☆101Feb 29, 2024Updated 2 years ago
Alternatives and similar repositories for security-reviews
Users that are interested in security-reviews are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Mar 13, 2024Updated 2 years ago
- Machine-readable specification for the attestation of security-relevant data.☆81Sep 12, 2026Updated last week
- The purpose of the Metrics & Metadata (formerly Identifying Security Threats) working group is to enable stakeholders to have informed co…☆222Apr 23, 2024Updated 2 years ago
- ☆23Oct 26, 2021Updated 4 years ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆208Sep 12, 2026Updated last week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆229Feb 4, 2026Updated 7 months ago
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,067Updated this week
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆142Aug 19, 2026Updated last month
- Supply Chain Query Tool☆13May 25, 2022Updated 4 years ago
- Helping allocate resources to secure the critical open source projects we all depend on.☆411Sep 2, 2026Updated 2 weeks ago
- A TUF repository and signing tool☆51Updated this week
- Given a buildinfo file from a Debian package, generate instructions for attempting to reproduce the binary packages built from the associ…☆17Sep 24, 2022Updated 3 years ago
- OpenSSF Security Tooling Working Group☆326Jul 6, 2025Updated last year
- ☆33Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆35Apr 4, 2023Updated 3 years ago
- Simple and pratical security gate for Github Security Alerts☆22Sep 4, 2026Updated 2 weeks ago
- A command-line interface tool for creating, managing, and verifying Content Provenance and Authenticity (C2PA) manifests for machine lear…☆22Sep 14, 2026Updated last week
- Go implementation of The Update Framework heavily influenced by python-tuf☆14Mar 7, 2024Updated 2 years ago
- Supply Chain Integrity Model☆108Jun 12, 2023Updated 3 years ago
- in-toto Enhancements☆20Feb 17, 2025Updated last year
- SLSA level 3 action☆12Apr 26, 2024Updated 2 years ago
- Privateer is a plugin-based framework for security & compliance evaluations.☆26Updated this week
- Collection of tools for analyzing open source packages.☆371Jul 31, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Cryptographic and general-purpose routines for Golang Secure Systems Lab projects at NYU☆30Updated this week
- Open Source Vulnerability schema.☆272Updated this week
- Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.☆21Sep 4, 2026Updated 2 weeks ago
- The Great Multi-Factor Authentication (MFA) Distribution Project of the Open Source Security Foundation (OpenSSF). We work to distribute …☆54Dec 28, 2021Updated 4 years ago
- Kubernetes Security Testing Guide☆28Apr 22, 2024Updated 2 years ago
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Jul 5, 2023Updated 3 years ago
- Application Security Workflow Automation using Docker and Kubernetes☆23Dec 11, 2022Updated 3 years ago
- OASIS TC Open Repository: A GitHub repository for management of non-normative information about the work of the CSAF Technical Committee,…☆22Updated this week
- Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)☆206Aug 21, 2026Updated last month
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- A Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakes☆43Nov 28, 2025Updated 9 months ago
- Witness Examples☆12Feb 27, 2024Updated 2 years ago
- standard for Uptane☆44Jul 24, 2026Updated last month
- A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.☆33Oct 13, 2024Updated last year
- threatspec - continuous threat modeling, through code☆390Dec 30, 2020Updated 5 years ago
- Sigstore's Protocol Buffer specifications☆37Sep 14, 2026Updated last week
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆19Sep 2, 2026Updated 2 weeks ago