OpenSSF Working Group on Securing Software Repositories
☆130Apr 6, 2026Updated 3 months ago
Alternatives and similar repositories for wg-securing-software-repos
Users that are interested in wg-securing-software-repos are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- OpenSSF Endusers Working Group☆28Mar 21, 2024Updated 2 years ago
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,053Updated this week
- OpenSSF Security Tooling Working Group☆325Jul 6, 2025Updated last year
- Technical Advisory Council☆149Updated this week
- Evangelizing the mission and work of the OpenSSF and building strong community outreach around end-users, open-source maintainers, and co…☆26May 2, 2024Updated 2 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆207Jan 15, 2026Updated 6 months ago
- Umbrella Repository Service for TUF☆67Jul 21, 2026Updated last week
- The purpose of the Metrics & Metadata (formerly Identifying Security Threats) working group is to enable stakeholders to have informed co…☆223Apr 23, 2024Updated 2 years ago
- A CLI tool for creating secure by design/default source repos.☆28Jul 29, 2024Updated 2 years ago
- Helping allocate resources to secure the critical open source projects we all depend on.☆403May 8, 2025Updated last year
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆587Updated this week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆121Feb 28, 2026Updated 5 months ago
- ☆27Mar 17, 2026Updated 4 months ago
- Language-agnostic SLSA provenance generation for Github Actions☆589Mar 29, 2026Updated 4 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Reference GitHub Workflows for SBOM generation from the CISA SBOM Generation Reference Implementation Tiger Team☆34Feb 2, 2026Updated 5 months ago
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆240May 26, 2025Updated last year
- Low friction library for application configuration.☆14Sep 1, 2022Updated 3 years ago
- Command line interface for Kusari☆16Updated this week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆49Updated this week
- ☆16Jul 12, 2026Updated 2 weeks ago
- ☆87Dec 10, 2025Updated 7 months ago
- in-toto Attestation Framework☆356Updated this week
- Machine-readable specification for the attestation of security-relevant data.☆81Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Run ORT in your GitHub action workflow to do licensing, security and best practices checks and generate reports/SBOMs☆34Jul 21, 2026Updated last week
- Open Source Maturity Model☆17Apr 30, 2024Updated 2 years ago
- OpenSSF Scorecard for top Python packages☆16Jul 22, 2026Updated last week
- Supply-chain Levels for Software Artifacts☆1,896Updated this week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆34Apr 22, 2025Updated last year
- Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.☆89Updated this week
- Open Source Package Analysis☆903Updated this week
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆151Jul 10, 2026Updated 2 weeks ago
- Campaigns of (mostly) malicious packages - currently only in PyPI☆15Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆32Jul 21, 2026Updated last week
- Minimal container registry☆49Jul 22, 2026Updated last week
- Binary builds for dep-scan - The Dependency Scanner☆10Apr 1, 2024Updated 2 years ago
- A universal SBOM representation in protocol buffers☆326Updated this week
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆208Updated this week
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆183May 1, 2026Updated 2 months ago
- Measure the logical heft of your Python dependencies☆28Updated this week