renovatebot / osv-offlineLinks
A collection of packages for using GitHub security advisories in Node.js.
☆16Updated this week
Alternatives and similar repositories for osv-offline
Users that are interested in osv-offline are comparing it to the libraries listed below
Sorting:
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆35Updated 3 weeks ago
- Auto-generating docs repository for Renovate Bot☆52Updated this week
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆134Updated this week
- SARIF Microsoft Visual Studio Code extension☆117Updated this week
- JavaScript implementation of the package url spec☆28Updated 2 months ago
- The model for the information captured in SPDX version 3 standard.☆83Updated last week
- Action for generating attestations for workflow artifacts☆49Updated this week
- OpenSSF Endusers Working Group☆28Updated last year
- The service side of clearlydefined.io☆47Updated this week
- Produce an Open Source Vulnerability JSON file based on information in an SPDX document☆64Updated last year
- SBOM Edit - Conditional edits and merging of SBOMs☆69Updated this week
- The containerbase project's base image source☆43Updated last week
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆28Updated last year
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆96Updated last year
- Enrich SBOMs with data from third party services☆175Updated 2 months ago
- Renovate base docker image☆12Updated last week
- GitHub CLI extension for working with CodeQL☆32Updated 3 months ago
- Renovate internal build tools☆9Updated this week
- Code-signing for npm packages☆162Updated this week
- OpenSSF Working Group on Securing Software Repositories☆107Updated last week
- Generate VEX (Vulnerability Exploitability Exchange) CycloneDX documents☆22Updated 4 months ago
- Entitlements plugin for a robust audit log☆21Updated last month
- Plugin for supporting SPDX in a Maven build.☆56Updated last month
- Technical Advisory Council☆124Updated last week
- A React-based component for viewing SARIF files.☆95Updated 6 months ago
- Search Rekor for entries☆34Updated 2 months ago
- A light-weight app to audit and inventory large codebases for open source license compliance.☆65Updated this week
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆185Updated last year
- Open Source Vulnerability schema.☆199Updated last week
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆194Updated 2 months ago