yahoo / GitHub-Security-Alerts-WorkflowLinks
Automation to Incorporate GitHub Security Alerts Into your Business Workflow
☆21Updated 2 years ago
Alternatives and similar repositories for GitHub-Security-Alerts-Workflow
Users that are interested in GitHub-Security-Alerts-Workflow are comparing it to the libraries listed below
Sorting:
- Generate SBOMs with gh CLI☆197Updated 8 months ago
- ☆83Updated last year
- GitHub Secret Scanning Auto Remediator (GSSAR)☆46Updated 3 weeks ago
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆74Updated last year
- GitHub Advanced Security Policy as Code☆94Updated last month
- GitHub Advance Security Compliance Action☆134Updated 3 years ago
- Synchronize GitHub Code Scanning alerts to Jira issues☆96Updated 2 months ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆110Updated last week
- Enrich SBOMs with data from third party services☆213Updated last month
- Official GitHub Action for OpenSSF Scorecard.☆355Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆237Updated last year
- Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.☆111Updated 2 weeks ago
- Orchestrate GitHub Actions Security☆304Updated 2 weeks ago
- Securing Alice's, Bob's and Carl's software supply chain using in-toto☆104Updated last week
- ☆74Updated last month
- Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.☆78Updated this week
- Examples of SPDX files for software combinations☆141Updated 2 months ago
- GitHub Action that provides an Organization Membership Audit☆42Updated 2 years ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆42Updated last week
- Sync GitHub teams to groups in Active Directory, LDAP, Okta, OneLogin or AzureAD when using any authentication method for GitHub.☆209Updated 10 months ago
- Machine-readable specification for the attestation of security-relevant data.☆71Updated 3 weeks ago
- Technical Advisory Council☆133Updated last week
- SPDX Merge tool☆50Updated 9 months ago
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆222Updated 8 months ago
- GitHub Action for filtering Code Scanning alerts by path and id☆36Updated last year
- sbomasm: The Complete SBOM Management Toolkit☆100Updated last week
- Unit testing framework for test driven security of AWS, GCP, Heroku and more.☆108Updated last week
- GitHub Action for creating software bill of materials using Syft.☆217Updated last week
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆195Updated 2 weeks ago
- OpenVEX Specification☆164Updated 2 weeks ago