pixee / codemodder-specsLinks
☆14Updated 9 months ago
Alternatives and similar repositories for codemodder-specs
Users that are interested in codemodder-specs are comparing it to the libraries listed below
Sorting:
- A GitHub Action that allows Pixee to fix issues found by other code scanners☆15Updated 11 months ago
- A set of security APIs meant to help secure Java code☆24Updated 2 weeks ago
- Security toolkit for the Python community☆15Updated 10 months ago
- ☆120Updated 8 months ago
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆184Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆235Updated last year
- a framework for building java codemods☆40Updated last week
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆258Updated this week
- Enrich SBOMs with data from third party services☆206Updated last week
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆195Updated 3 weeks ago
- Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects☆210Updated last week
- PURL to CPE Relationship mapping project.☆106Updated this week
- Reproducible Central: rebuild instructions for artifacts published to (Maven) Central Repository☆131Updated this week
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆100Updated 2 weeks ago
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆465Updated last week
- Utility that provides an API platform for validating, querying and managing BOM data☆124Updated 3 months ago
- OpenVEX Specification☆164Updated 6 months ago
- A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositorie…☆378Updated last week
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆339Updated 2 years ago
- sigstore maven plugin☆19Updated last year
- sbomasm: The Complete SBOM Management Toolkit☆97Updated 2 weeks ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆40Updated last month
- Language-agnostic SLSA provenance generation for Github Actions☆531Updated 2 months ago
- in-toto Attestation Framework☆316Updated last week
- CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.☆436Updated 3 weeks ago
- Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.☆75Updated last week
- A scalable server implementation of the OSS Review Toolkit.☆46Updated last week
- GitHub Advanced Security Policy as Code☆91Updated 2 weeks ago
- Automation to Incorporate GitHub Security Alerts Into your Business Workflow☆21Updated 2 years ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆511Updated last week