A community collection of security reviews of open source software components.
☆100Feb 29, 2024Updated 2 years ago
Alternatives and similar repositories for security-reviews
Users that are interested in security-reviews are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Mar 13, 2024Updated 2 years ago
- Machine-readable specification for the attestation of security-relevant data.☆81Jul 27, 2026Updated 2 weeks ago
- The purpose of the Metrics & Metadata (formerly Identifying Security Threats) working group is to enable stakeholders to have informed co…☆222Apr 23, 2024Updated 2 years ago
- Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.☆137Jul 31, 2026Updated last week
- ☆23Oct 26, 2021Updated 4 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆207Jan 15, 2026Updated 6 months ago
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆225Feb 4, 2026Updated 6 months ago
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,060Updated this week
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆142Apr 20, 2026Updated 3 months ago
- Supply Chain Query Tool☆13May 25, 2022Updated 4 years ago
- Helping allocate resources to secure the critical open source projects we all depend on.☆404May 8, 2025Updated last year
- A TUF repository and signing tool☆51Aug 3, 2026Updated last week
- Given a buildinfo file from a Debian package, generate instructions for attempting to reproduce the binary packages built from the associ…☆17Sep 24, 2022Updated 3 years ago
- OpenSSF Security Tooling Working Group☆326Jul 6, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆32Updated this week
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆35Apr 4, 2023Updated 3 years ago
- Simple and pratical security gate for Github Security Alerts☆21Jul 20, 2026Updated 3 weeks ago
- Solidity bootcamp☆14Jan 27, 2022Updated 4 years ago
- A bot that watches a website or GitHub assets for changes and communicates them to Slack.☆11Apr 5, 2019Updated 7 years ago
- Supply Chain Integrity Model☆108Jun 12, 2023Updated 3 years ago
- A command-line interface tool for creating, managing, and verifying Content Provenance and Authenticity (C2PA) manifests for machine lear…☆22Jul 27, 2026Updated 2 weeks ago
- Go implementation of The Update Framework heavily influenced by python-tuf☆14Mar 7, 2024Updated 2 years ago
- in-toto Enhancements☆20Feb 17, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- SLSA level 3 action☆12Apr 26, 2024Updated 2 years ago
- Privateer is a plugin-based framework for security & compliance evaluations.☆23Updated this week
- Collection of tools for analyzing open source packages.☆370Jul 31, 2026Updated last week
- Cryptographic and general-purpose routines for Golang Secure Systems Lab projects at NYU☆32Jul 21, 2026Updated 3 weeks ago
- Open Source Vulnerability schema.☆266Updated this week
- Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.☆21Jul 16, 2026Updated 3 weeks ago
- The Great Multi-Factor Authentication (MFA) Distribution Project of the Open Source Security Foundation (OpenSSF). We work to distribute …☆54Dec 28, 2021Updated 4 years ago
- Kubernetes Security Testing Guide☆27Apr 22, 2024Updated 2 years ago
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Jul 5, 2023Updated 3 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- OASIS TC Open Repository: A GitHub repository for management of non-normative information about the work of the CSAF Technical Committee,…☆22Jul 28, 2026Updated 2 weeks ago
- Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)☆205Jul 15, 2026Updated 3 weeks ago
- A Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakes☆43Nov 28, 2025Updated 8 months ago
- Witness Examples☆12Feb 27, 2024Updated 2 years ago
- A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.☆33Oct 13, 2024Updated last year
- threatspec - continuous threat modeling, through code☆390Dec 30, 2020Updated 5 years ago
- A straightforward tool for exploiting SMTP Smuggling vulnerabilities.☆14Jul 22, 2024Updated 2 years ago