psf / sboms-for-python-packagesLinks
Software Bill-of-Materials documents for Python packages
☆44Updated 8 months ago
Alternatives and similar repositories for sboms-for-python-packages
Users that are interested in sboms-for-python-packages are comparing it to the libraries listed below
Sorting:
- A GitHub Action for sigstore-python☆63Updated this week
- A Sigstore client written in Python☆296Updated this week
- Packaging improvements that could be funded☆56Updated 2 years ago
- Dlint is a tool for encouraging best coding practices and helping ensure Python code is secure.☆171Updated last year
- Data about packages and maintainers on PyPI☆129Updated last month
- Pytest plugin to fake subprocess.☆114Updated last week
- Create reproducible installations for a virtual environment from a lock file☆85Updated 2 months ago
- A tool for running a PEP-503 simple Python package repository, including features such as dist metadata (PEP-658) and JSON API (PEP-691)☆22Updated last month
- Extensions for Sphinx which allow substitutions☆41Updated this week
- ☆55Updated last year
- a GitHub action to install (pre-release) pythons from deadsnakes☆57Updated last week
- Extract information from wheels☆24Updated 3 weeks ago
- Check your Python environments for vulnerable Open Source packages with OSS Index or Sonatype Nexus Lifecycle.☆130Updated 5 months ago
- A parser for Python dependency files☆65Updated 11 months ago
- Python implementation of the package url spec. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase…☆79Updated 2 months ago
- Add inline tabbed content to your Sphinx documentation. (maintained, though extremely stable as of Jan 2022)☆88Updated last week
- Check for stylistic and formal issues in .rst and .py files included in the documentation☆93Updated last week
- Resolve abstract dependencies into concrete ones☆159Updated 2 weeks ago
- ☆198Updated 2 weeks ago
- The toolkit for building extension modules☆25Updated 2 years ago
- Render CLI arguments (sub-commands friendly) defined by the argparse module.☆25Updated last week
- Simple, composable command runner for Python projects☆36Updated 2 weeks ago
- Security audit Python project dependencies against security advisory databases.☆66Updated 3 months ago
- Update GitHub Actions version pins in GitHub workflow files.☆38Updated 4 months ago
- PyPI Simple Repository API client library☆40Updated 3 weeks ago
- Vendy is a tool for vendoring third-party packages into your project.☆17Updated last year
- Utility library to parse, normalize and compare License expressions for Python using a boolean logic engine. For expressions using SPDX …☆70Updated 3 months ago
- Validate configuration and produce human readable error messages☆50Updated last week
- This is a repository of vulnerability advisories for projects in scope for the Python Software Foundation CVE Numbering Authority (CNA)☆38Updated 2 weeks ago
- Vendorize packages from PyPI☆106Updated last year