safedep / vet
Tool to achieve policy driven vetting of open source dependencies
☆247Updated this week
Alternatives and similar repositories for vet:
Users that are interested in vet are comparing it to the libraries listed below
- Runtime Security Solution for your CI/CD Pipeline☆93Updated 4 months ago
- boostsecurityio/poutine☆243Updated last week
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆130Updated 11 months ago
- A tool for preventing the installation of malicious PyPI and npm packages☆108Updated last month
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆103Updated 8 months ago
- Enrich SBOMs with data from third party services☆151Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆224Updated 5 months ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆170Updated last month
- Gram is Klarna's own threat model diagramming tool☆291Updated this week
- Software Supply Chain Security Platform☆306Updated this week
- A tool to check the security settings of Github Organizations.☆70Updated last year
- ☆122Updated this week
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆281Updated this week
- Validate the isolation posture of your container environment.☆227Updated this week
- Format agnostic SBOM tooling☆94Updated this week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- A security layer for Git repositories☆473Updated this week
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆82Updated this week
- Documenting your Threat Models with HCL☆412Updated 4 months ago
- OpenVEX Specification☆139Updated 6 months ago
- Evaluate source control (GitHub) security posture☆249Updated last year
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆302Updated last year
- SBOM quality score - Quality metrics for your sboms☆192Updated this week
- Utility that provides an API platform for validating, querying and managing BOM data☆98Updated 2 months ago
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆144Updated last month
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆113Updated last year
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆37Updated last month
- A tool to create, transform and attest VEX metadata☆126Updated this week
- ☆161Updated 4 months ago
- Protect against subdomain takeover☆92Updated 7 months ago