slsa-framework / governanceLinks
SLSA implementation of Community Specification governance
☆24Updated 3 weeks ago
Alternatives and similar repositories for governance
Users that are interested in governance are comparing it to the libraries listed below
Sorting:
- Synchronize GitHub Code Scanning alerts to Jira issues☆96Updated this week
- Technical Advisory Council☆134Updated last week
- Website and API for OpenSSF Scorecard☆28Updated this week
- ☆16Updated 7 months ago
- This repo contains the source for the CVE Services API.☆229Updated this week
- Generate SBOMs with gh CLI☆198Updated 8 months ago
- SLSA Proposals☆11Updated 2 years ago
- Manage a uniform team of security managers for every organization in your enterprise☆24Updated last week
- Entitlements plugin for a robust audit log☆23Updated this week
- Supply Chain Integrity Model☆106Updated 2 years ago
- SLSA Azure DevOps Pipelines Extension☆29Updated last year
- A proof-of-concept SLSA provenance generator for Jenkins☆24Updated last year
- ☆115Updated 5 months ago
- This repository contains a sample script which can be used to enable security vulnerability alerts in all of the repositories in a given …☆80Updated last year
- Continuous Compliance makes it possible to enforce company policy on repositories. Continuous Compliance will automatically check your re…☆22Updated 2 months ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆196Updated 3 weeks ago
- TUF repository for Sigstore trust root☆117Updated this week
- Utility for bulk image, license, package, and vulnerability discovery in containerize workloads on GCP. Includes CLI and Service with cus…☆13Updated last year
- Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.☆112Updated this week
- General sigstore community repo☆44Updated this week
- OpenID Shared Signals Working Group Repository☆72Updated last month
- GitHub Secret Scanning Auto Remediator (GSSAR)☆46Updated last month
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆135Updated 2 months ago
- Bypass approval and checks in order to merge an emergency change to the main branch with audit controls.☆56Updated this week
- OpenSSF Endusers Working Group☆28Updated last year
- ☆138Updated last week
- Source for official CVE Program policy documents.☆18Updated last week
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆210Updated this week
- GitHub action to scan container images with Palo Alto Networks' Prisma Cloud☆58Updated last month
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆33Updated 3 years ago