renovatebot / osv-offline
A collection of packages for using GitHub security advisories in Node.js.
☆12Updated this week
Related projects ⓘ
Alternatives and complementary repositories for osv-offline
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆33Updated this week
- Auto-generating docs repository for Renovate Bot☆43Updated this week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆32Updated 4 months ago
- GitHub app for SBOM creation using cdxgen and upload to Dependency-Track☆15Updated this week
- The containerbase project's base image source☆35Updated this week
- Generate CycloneDX Software Bill of Materials (SBOM) from webpack bundles at compile time.☆24Updated this week
- ☆23Updated 3 months ago
- Curations and configuration files for the OSS Review Toolkit.☆16Updated this week
- OpenSSF Endusers Working Group☆28Updated 7 months ago
- Plugin for supporting SPDX in a Maven build.☆44Updated last week
- The SCANOSS SBOM Workbench graphical user interface to scan and audit your source code.☆47Updated last week
- The model for the information captured in SPDX version 3 standard.☆70Updated 2 weeks ago
- Search an SBOM for licenses and the packages they belong to☆70Updated this week
- Repo for building the renovate/renovate:full image☆39Updated 9 months ago
- GitHub Action to get a license overview in SPDX format☆14Updated 2 years ago
- Public website cyclonedx.org☆9Updated this week
- ☆111Updated 5 months ago
- Action for generating attestations for workflow artifacts☆33Updated this week
- Solicitor is a tool enabling management of licenses of software dependencies☆22Updated 3 weeks ago
- TUF repository for Sigstore trust root☆88Updated this week
- Renovate docker slim image☆74Updated 9 months ago
- The service side of clearlydefined.io☆45Updated this week
- Utility that converts SBOM documents from CycloneDX to SPDX☆29Updated 9 months ago
- Incubating project for decoupling responsibilities from Dependency-Track's monolithic API server into separate, scalable services.☆61Updated last week
- A BOM repository server for distributing CycloneDX BOMs☆74Updated 7 months ago
- ☆30Updated last week
- OpenSSF Working Group on Securing Software Repositories☆91Updated last week
- Log monitor for Rekor to verify immutability and monitor entries☆25Updated this week
- A GitHub Action to update the changelog and bump the version of your project for Dependabot pull requests.☆15Updated this week
- A taxonomy of all official CycloneDX property namespaces and names☆14Updated last week