A community collection of security reviews of open source software components.
☆99Feb 29, 2024Updated 2 years ago
Alternatives and similar repositories for security-reviews
Users that are interested in security-reviews are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Mar 13, 2024Updated 2 years ago
- Machine-readable specification for the attestation of security-relevant data.☆80Jul 15, 2026Updated last week
- The purpose of the Metrics & Metadata (formerly Identifying Security Threats) working group is to enable stakeholders to have informed co…☆223Apr 23, 2024Updated 2 years ago
- ☆23Oct 26, 2021Updated 4 years ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆207Jan 15, 2026Updated 6 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆223Feb 4, 2026Updated 5 months ago
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,051Jul 13, 2026Updated last week
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆140Apr 20, 2026Updated 3 months ago
- Supply Chain Query Tool☆13May 25, 2022Updated 4 years ago
- Helping allocate resources to secure the critical open source projects we all depend on.☆403May 8, 2025Updated last year
- A TUF repository and signing tool☆48Updated this week
- Given a buildinfo file from a Debian package, generate instructions for attempting to reproduce the binary packages built from the associ…☆17Sep 24, 2022Updated 3 years ago
- OpenSSF Security Tooling Working Group☆325Jul 6, 2025Updated last year
- ☆31Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆35Apr 4, 2023Updated 3 years ago
- A bot that watches a website or GitHub assets for changes and communicates them to Slack.☆11Apr 5, 2019Updated 7 years ago
- Supply Chain Integrity Model☆108Jun 12, 2023Updated 3 years ago
- Go implementation of The Update Framework heavily influenced by python-tuf☆14Mar 7, 2024Updated 2 years ago
- in-toto Enhancements☆20Feb 17, 2025Updated last year
- SLSA level 3 action☆12Apr 26, 2024Updated 2 years ago
- Privateer is a plugin-based framework for security & compliance evaluations.☆23Updated this week
- Cryptographic and general-purpose routines for Golang Secure Systems Lab projects at NYU☆32Updated this week
- ☆22Mar 23, 2026Updated 3 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.☆21Updated this week
- The Great Multi-Factor Authentication (MFA) Distribution Project of the Open Source Security Foundation (OpenSSF). We work to distribute …☆54Dec 28, 2021Updated 4 years ago
- Kubernetes Security Testing Guide☆27Apr 22, 2024Updated 2 years ago
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Jul 5, 2023Updated 3 years ago
- Application Security Workflow Automation using Docker and Kubernetes☆23Dec 11, 2022Updated 3 years ago
- OASIS TC Open Repository: A GitHub repository for management of non-normative information about the work of the CSAF Technical Committee,…☆22Jul 3, 2026Updated 2 weeks ago
- Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)☆204Jul 15, 2026Updated last week
- A Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakes☆43Nov 28, 2025Updated 7 months ago
- standard for Uptane☆44Apr 20, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.☆30Oct 13, 2024Updated last year
- threatspec - continuous threat modeling, through code☆389Dec 30, 2020Updated 5 years ago
- A straightforward tool for exploiting SMTP Smuggling vulnerabilities.☆14Jul 22, 2024Updated 2 years ago
- ☆17Jan 3, 2021Updated 5 years ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆19Updated this week
- An http proxy for reproducibility.☆19Jan 10, 2023Updated 3 years ago
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆23Updated this week