psf / sboms-for-python-packagesLinks
Software Bill-of-Materials documents for Python packages
☆44Updated 9 months ago
Alternatives and similar repositories for sboms-for-python-packages
Users that are interested in sboms-for-python-packages are comparing it to the libraries listed below
Sorting:
- A GitHub Action for sigstore-python☆62Updated this week
- A Sigstore client written in Python☆299Updated this week
- Data about packages and maintainers on PyPI☆129Updated 2 months ago
- Packaging improvements that could be funded☆56Updated 2 years ago
- Dlint is a tool for encouraging best coding practices and helping ensure Python code is secure.☆171Updated 2 weeks ago
- A tool for running a PEP-503 simple Python package repository, including features such as dist metadata (PEP-658) and JSON API (PEP-691)☆22Updated last month
- Create reproducible installations for a virtual environment from a lock file☆85Updated 2 weeks ago
- Resolve abstract dependencies into concrete ones☆159Updated last month
- A parser for Python dependency files☆65Updated last year
- ☆55Updated last year
- Verify certificates using OS trust stores☆209Updated last week
- Security audit Python project dependencies against security advisory databases.☆66Updated 3 months ago
- Pytest plugin to fake subprocess.☆115Updated last month
- Update GitHub Actions version pins in GitHub workflow files.☆38Updated 4 months ago
- Extensions for Sphinx which allow substitutions☆41Updated last week
- Extract information from wheels☆24Updated 2 weeks ago
- Validation library for simple check on `pyproject.toml`☆191Updated last week
- Validate configuration and produce human readable error messages☆50Updated 2 weeks ago
- Check for stylistic and formal issues in .rst and .py files included in the documentation☆95Updated 3 weeks ago
- A tool to generate a SBOM (Software Bill of Materials) for an installed Python module☆36Updated 2 months ago
- The toolkit for building extension modules☆25Updated 2 years ago
- PEP 621 metadata parsing☆43Updated last week
- Check your Python environments for vulnerable Open Source packages with OSS Index or Sonatype Nexus Lifecycle.☆132Updated 6 months ago
- Build and Inspect Python Packages in GitHub Actions☆208Updated last week
- Simple, composable command runner for Python projects☆36Updated last week
- A web interface to browse and search packages in any simple package repository (PEP-503), inspired by PyPI / warehouse☆16Updated 3 weeks ago
- CLI to show end-of-life dates for a number of products.☆135Updated last week
- This is a repository of vulnerability advisories for projects in scope for the Python Software Foundation CVE Numbering Authority (CNA)☆38Updated this week
- PyPI Simple Repository API client library☆41Updated last week
- a GitHub action to install (pre-release) pythons from deadsnakes☆58Updated last week