pixee / codemodder-specs
☆14Updated 3 weeks ago
Alternatives and similar repositories for codemodder-specs:
Users that are interested in codemodder-specs are comparing it to the libraries listed below
- A GitHub Action that allows Pixee to fix issues found by other code scanners☆14Updated 2 months ago
- Security toolkit for the Python community☆14Updated last month
- a framework for building java codemods☆40Updated last month
- Implementation of the Pixee CLI☆31Updated last week
- A set of security APIs meant to help secure Java code☆20Updated 3 months ago
- Enrich SBOMs with data from third party services☆162Updated last month
- ☆114Updated 9 months ago
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆148Updated this week
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆92Updated last week
- GitHub Advanced Security Policy as Code☆82Updated last week
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆180Updated last year
- GitHub Advance Security Compliance Action☆133Updated 2 years ago
- Generate VEX (Vulnerability Exploitability Exchange) CycloneDX documents☆20Updated 2 months ago
- sigstore maven plugin☆18Updated 8 months ago
- GitHub app for SBOM creation using cdxgen and upload to Dependency-Track☆18Updated this week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆33Updated last month
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆186Updated this week
- OpenVEX Specification☆144Updated this week
- PURL to CPE Relationship mapping project.☆85Updated this week
- java clients for sigstore☆54Updated this week
- Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.☆94Updated last week
- GitHub Action for submitting Maven dependencies☆49Updated this week
- Examples of Custom Secret Scanning Patterns☆159Updated last month
- Technical Advisory Council☆118Updated this week
- OpenSSF Working Group on Securing Software Repositories☆100Updated 5 months ago
- Safelog4j is an instrumentation-based security tool to help teams discover, verify, and solve log4shell vulnerabilities without scanning …☆41Updated 9 months ago
- ☆100Updated 6 months ago
- Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects☆183Updated this week
- Generate thousands of pull requests to fix widespread security vulnerabilities across GitHub.☆34Updated last month
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Updated last year