pixee / codemodder-specs
☆14Updated this week
Alternatives and similar repositories for codemodder-specs:
Users that are interested in codemodder-specs are comparing it to the libraries listed below
- A GitHub Action that allows Pixee to fix issues found by other code scanners☆14Updated this week
- Security toolkit for the Python community☆14Updated 2 months ago
- a framework for building java codemods☆39Updated this week
- Implementation of the Pixee CLI☆29Updated last week
- A set of security APIs meant to help secure Java code☆19Updated last month
- ☆112Updated 7 months ago
- Generate thousands of pull requests to fix widespread security vulnerabilities across GitHub.☆34Updated 2 months ago
- Gradle plugin that scans the dependencies of a Gradle project using Sonatype platforms: OSS Index and Lifecycle.☆77Updated 2 weeks ago
- A taxonomy of all official CycloneDX property namespaces and names☆14Updated last month
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆141Updated this week
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆83Updated this week
- Generate SBOMs with gh CLI☆175Updated 3 months ago
- PURL to CPE Relationship mapping project.☆82Updated this week
- GitHub Action for submitting Maven dependencies☆48Updated 3 months ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆178Updated 11 months ago
- Python implementation of OWASP CycloneDX☆71Updated this week
- Enrich SBOMs with data from third party services☆151Updated last week
- Measure release insights and recommendations for open-source dependencies. Note: this project is archived.☆11Updated 2 years ago
- GitHub Advanced Security Policy as Code☆76Updated last week
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆183Updated last month
- Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects☆166Updated this week
- Feed parsing for language package manager updates☆76Updated last month
- Automation to Incorporate GitHub Security Alerts Into your Business Workflow☆23Updated last year
- Language-agnostic SLSA provenance generation for Github Actions☆438Updated 2 weeks ago
- java clients for sigstore☆48Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆224Updated 5 months ago
- OpenRewrite's Gradle plugin.☆68Updated this week
- Produce an Open Source Vulnerability JSON file based on information in an SPDX document☆62Updated 7 months ago
- ☆33Updated 4 months ago
- Gradle Plugin for Extracting Dependency Information to send to GitHub☆85Updated this week