awesome-repositories.com
Blog
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektÜber unsRanking-MethodikPresseMCP-Server
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
ossf avatar

ossf/scorecard

0
View on GitHub↗
5,527 Stars·665 Forks·Go·Apache-2.0·2 Aufrufescorecard.dev↗

Scorecard

Scorecard ist ein Open-Source-Sicherheitsscanner und ein Tool zur Analyse der Software-Lieferkette, das den Sicherheitsstatus von Projekten durch die Berechnung von Risikometriken basierend auf Best Practices bewertet. Es fungiert als Dashboard für die Sicherheitsgesundheit und visualisiert Sicherheitslücken durch Scores und Badges, um Maintainer bei der Identifizierung von Schwachstellen zu unterstützen.

Das Projekt bietet ein System zur Überwachung der Repository-Sicherheit durch einen GitHub-Action-Sicherheitsauditor, der Maintainer alarmiert, wenn Sicherheits-Scores sinken. Es bietet zudem einen Mechanismus für Anleitungen zur Behebung von Schwachstellen, der identifizierte Sicherheitslücken auf präskriptive Anweisungen zur Verbesserung der Entwicklungspraktiken abbildet.

Das Tool deckt eine breite Oberfläche an Funktionen ab, einschließlich Open-Source-Sicherheitsaudits, CI/CD-Sicherheitsautomatisierung und der Analyse von Drittanbieter-Repositories zur Risikobewertung vor der Integration. Es unterstützt verschiedene Schnittstellen für die Interaktion, einschließlich eines Command-Line-Interfaces für Scans und eines REST-Interfaces zum Abrufen vorab berechneter Sicherheitsmetriken.

Features

  • Open Source Security Scanners - Evaluates the security posture of open source projects by calculating risk metrics based on industry best practices.
  • Security Posture Checklists - Evaluates source code and build processes to generate an aggregate security score and risk level.
  • Security Auditors - Provides a GitHub Action that monitors repository changes and alerts maintainers when security scores drop.
  • CI/CD Security Metrics Automation - Integrates security health checks into CI pipelines to detect regressions and alert maintainers.
  • Open Source Security - Evaluates the security posture of open source projects by scanning code and build processes.
  • Security Guides - Provides specific prompts and instructions to resolve identified security gaps.
  • Repository Security Health Tracking - Tracks security scores over time using automated badges and reports to maintain project posture.
  • Remediation Guidance - Maps security failures to prescriptive instructions to help maintainers improve their project's security posture.
  • Software Supply Chain Security - Analyzes third party dependencies and repositories to assess risk in the software supply chain.
  • Third Party Dependency Risk Assessment - Scans third-party repositories to assess their security posture before they are added as dependencies.
  • Security Findings Visualizations - Renders detailed graphical security analyses to help users identify and resolve security gaps.
  • Visual Badges - Generates auto-updating visual badges for project documentation to represent security ratings.
  • Repository Content Scanning - Enables security analysis of target projects via a terminal interface using repository links.
  • CLI Scanning Interfaces - Provides a command line interface to execute security evaluations on target projects.
  • Security Analysis Dashboards - Visualizes security gaps through scores, badges, and remediation guidance via a dedicated reporting interface.
  • Security Monitoring - Integrates security scanning into version control workflows to issue alerts on repository changes.
  • Automated Security Scan Triggers - Automates security scans on every code commit through CI pipelines to alert maintainers of regressions.
  • GitHub Actions - Integrates security checks as a GitHub Action workflow step for immediate feedback on changes.
  • Security Automation Tools - Automates analysis of the security posture of open source projects.
  • Application Security - Provides security health metrics for open source projects.
  • Security and Vulnerability Scanning - Provides security health metrics for open source projects.

Star-Verlauf

Star-Verlauf für ossf/scorecardStar-Verlauf für ossf/scorecard

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI

Häufig gestellte Fragen

Was macht ossf/scorecard?

Scorecard ist ein Open-Source-Sicherheitsscanner und ein Tool zur Analyse der Software-Lieferkette, das den Sicherheitsstatus von Projekten durch die Berechnung von Risikometriken basierend auf Best Practices bewertet. Es fungiert als Dashboard für die Sicherheitsgesundheit und visualisiert Sicherheitslücken durch Scores und Badges, um Maintainer bei der Identifizierung von Schwachstellen zu unterstützen.

Was sind die Hauptfunktionen von ossf/scorecard?

Die Hauptfunktionen von ossf/scorecard sind: Open Source Security Scanners, Security Posture Checklists, Security Auditors, CI/CD Security Metrics Automation, Open Source Security, Security Guides, Repository Security Health Tracking, Remediation Guidance.

Welche Open-Source-Alternativen gibt es zu ossf/scorecard?

Open-Source-Alternativen zu ossf/scorecard sind unter anderem: kubescape/kubescape — Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for… github/advisory-database — The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and… snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… lyft/cartography — Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… anchore/grype — Grype is a command-line security scanner designed to identify known vulnerabilities within container images,…

Open-Source-Alternativen zu Scorecard

Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit Scorecard.
  • kubescape/kubescapeAvatar von kubescape

    kubescape/kubescape

    11,489Auf GitHub ansehen↗

    Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance risks. It functions as a comprehensive security suite incorporating a compliance scanner, a container image vulnerability scanner, an admission controller for policy enforcement, and a runtime security monitor. The platform distinguishes itself through runtime-aware vulnerability filtering, which maps libraries loaded in memory to determine if vulnerabilities are actually reachable. It also integrates with AI assistants via a Mo

    Gobest-practicedevopskubernetes
    Auf GitHub ansehen↗11,489
  • github/advisory-databaseAvatar von github

    github/advisory-database

    2,337Auf GitHub ansehen↗

    The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and track security vulnerability data across diverse open source software ecosystems. It functions as a unified source of truth for security advisories, providing machine-readable records that help developers and automated tools identify and manage threats within their software supply chains. The platform distinguishes itself by utilizing a version-controlled, git-based storage model that relies on pull-request-driven workflows for community curation and verification. By enforcing a s

    Auf GitHub ansehen↗2,337
  • lyft/cartographyAvatar von lyft

    lyft/cartography

    3,926Auf GitHub ansehen↗

    Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from diverse cloud, identity, and software-as-a-service providers to model complex relationships between resources, users, and security findings within a centralized graph database. By mapping these interdependencies, the platform enables organizations to gain visibility into their environment and identify potential security risks through graph traversal queries. The platform distinguishes itself through its ontology-based normalization and cross-platform entity correlation, which map he

    Python
    Auf GitHub ansehen↗3,926
  • snyk/snykAvatar von snyk

    snyk/snyk

    5,586Auf GitHub ansehen↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    TypeScript
    Auf GitHub ansehen↗5,586
  • Alle 30 Alternativen zu Scorecard anzeigen→