A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain
☆99Feb 11, 2025Updated last year
Alternatives and similar repositories for OSCAR
Users that are interested in OSCAR are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆35Apr 4, 2023Updated 3 years ago
- Polar is a secure and scalable knowledge graph framework, designed to address the challenges posed by building big data systems in highly…☆26Sep 1, 2026Updated 2 weeks ago
- Hands-on Exercises for "Dangerous attack paths: Modern Development Environment Security - Devices and CI/CD pipelines"☆45Sep 19, 2022Updated 4 years ago
- PURL to CPE Relationship mapping project.☆131Updated this week
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆19Sep 2, 2026Updated 2 weeks ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆151Jan 28, 2024Updated 2 years ago
- ☆11Apr 23, 2020Updated 6 years ago
- ☆28Aug 6, 2020Updated 6 years ago
- NVD API 2.0 client for CVE information☆14May 15, 2025Updated last year
- CLI tool to validate CVE v5 JSON records.☆16Jul 28, 2026Updated last month
- Extract useful semantic from CVE descriptions usinig NLP☆25Jan 4, 2023Updated 3 years ago
- A tool to generate a SBOM (Software Bill of Materials) for an installed Python module☆38Jun 4, 2026Updated 3 months ago
- A wrapper script for https://sploitus.com to scrape query results for tools and exploits☆14Mar 3, 2019Updated 7 years ago
- SLSA Proposals☆13Jan 29, 2024Updated 2 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Send GKE audit events to falco☆12Jan 8, 2023Updated 3 years ago
- Windows Event Log Knowledge Base☆36Jul 6, 2026Updated 2 months ago
- A project to visualize the software supply chain☆58Sep 9, 2023Updated 3 years ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆116Updated this week
- Rust implementation of SafePOSIX☆13May 13, 2025Updated last year
- A collection of packages for using security advisories from osv.dev in Node.js.☆23Updated this week
- Analysis Correlation Engine☆26Sep 8, 2019Updated 7 years ago
- ☆19Updated this week
- Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂☆120Dec 24, 2025Updated 8 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Toy browser on single process / thread☆33Aug 9, 2022Updated 4 years ago
- Microsoft Compound File Binary (CFB) file format Python IO☆15Apr 2, 2026Updated 5 months ago
- SBOM Explorer - Discover and pull public SBOMs☆21May 23, 2025Updated last year
- Remote Desktop Protocol .NET Console Application for Authenticated Command Execution☆11Jan 21, 2020Updated 6 years ago
- Scans SBOMs for vulnerabilities with Grype☆88Updated this week
- Enrich SBOMs with data from third party services☆240Aug 28, 2026Updated 3 weeks ago
- OASIS CSAF TC: Supporting version control for Work Product artifacts developed by members of TC, including prose specifications and secon…☆227Sep 13, 2026Updated last week
- A utility to force query DNS over DoH off of CloudFlare API when DNS block is in place☆10Aug 26, 2018Updated 8 years ago
- Collection of Go packages to work with SPDX files☆170Aug 24, 2026Updated 3 weeks ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- A Docker Compose Centric CI System☆12Oct 25, 2015Updated 10 years ago
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆151Sep 10, 2026Updated last week
- ☆12Aug 8, 2022Updated 4 years ago
- A place to systematically store software bill of materials (SBOM) documents.☆51Jun 1, 2023Updated 3 years ago
- Trivy plugin for OCI referrers☆23May 13, 2024Updated 2 years ago
- Exploit & Vulnerability Intelligence Repository☆25Jan 20, 2025Updated last year
- Simple SOAR (Security Orchestration, Automation and Response) framework integrated with OPA/Rego☆25Jul 7, 2025Updated last year