slsa-framework / governanceLinks
SLSA implementation of Community Specification governance
☆23Updated 8 months ago
Alternatives and similar repositories for governance
Users that are interested in governance are comparing it to the libraries listed below
Sorting:
- Generate SBOMs with gh CLI☆197Updated 7 months ago
- SLSA Proposals☆11Updated last year
- Technical Advisory Council☆134Updated last week
- SLSA Azure DevOps Pipelines Extension☆29Updated last year
- Supply Chain Integrity Model☆106Updated 2 years ago
- Synchronize GitHub Code Scanning alerts to Jira issues☆96Updated last month
- Utility for bulk image, license, package, and vulnerability discovery in containerize workloads on GCP. Includes CLI and Service with cus…☆13Updated last year
- Website and API for OpenSSF Scorecard☆29Updated last week
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆33Updated 3 years ago
- General sigstore community repo☆44Updated this week
- Github Action implementation of SLSA Provenance Generation☆50Updated this week
- ☆115Updated 5 months ago
- Manage a uniform team of security managers for every organization in your enterprise☆24Updated 2 weeks ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆41Updated last month
- Continuous Compliance makes it possible to enforce company policy on repositories. Continuous Compliance will automatically check your re…☆22Updated last month
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Updated 3 years ago
- ☆134Updated last week
- A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of mater…☆43Updated 2 years ago
- Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.☆110Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆236Updated last year
- ☆16Updated 6 months ago
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆135Updated last month
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆195Updated last month
- TUF repository for Sigstore trust root☆117Updated this week
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆22Updated 2 years ago
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆136Updated last week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆111Updated last month
- An SBOM query language and associated utilities