awesome-repositories.com
Blog
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to en/code-security

Open-source alternatives to Code Security

16 open-source projects similar to en/code-security, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Code Security alternative.

  • denysvuika/supply-chain-inspectorAvatar de DenysVuika

    DenysVuika/supply-chain-inspector

    3Voir sur GitHub↗

    A standalone, zero-dependency Node.js script for supply chain security analysis of npm dependencies.

    JavaScript
    Voir sur GitHub↗3
  • aquasecurity/chain-benchAvatar de aquasecurity

    aquasecurity/chain-bench

    774Voir sur GitHub↗

    An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

    Go
    Voir sur GitHub↗774
  • deislabs/ratifyAvatar de deislabs

    deislabs/ratify

    303Voir sur GitHub↗

    Artifact Ratification Framework (CNCF Sandbox)

    Go
    Voir sur GitHub↗303
  • ellerbrock/typescript-badgesE

    ellerbrock/typescript-badges

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • grafeas/kritisAvatar de grafeas

    grafeas/kritis

    710Voir sur GitHub↗

    Deploy-time Policy Enforcer for Kubernetes applications

    Go
    Voir sur GitHub↗710
  • in-toto/attestationAvatar de in-toto

    in-toto/attestation

    341Voir sur GitHub↗

    in-toto Attestation Framework

    Rust
    Voir sur GitHub↗341

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Find more with AI search
  • os-scar/overlayAvatar de os-scar

    os-scar/overlay

    228Voir sur GitHub↗

    Overlay

    JavaScript
    Voir sur GitHub↗228
  • sigstore/cosignAvatar de sigstore

    sigstore/cosign

    5,667Voir sur GitHub↗

    Cosign is a tool for signing and verifying software artifacts, primarily those stored in OCI-compatible registries such as container images, Helm charts, SBOMs, and Tekton bundles. It supports keyless signing using ephemeral keys and short-lived certificates from the Sigstore public-good infrastructure, associating signatures with an OpenID Connect identity rather than a long-lived cryptographic key. The project provides multiple signing and verification methods, including private keys, key pairs stored in KMS providers like AWS KMS and Azure Key Vault, and hardware security keys. It can sign

    Go
    Voir sur GitHub↗5,667
  • sigstore/fulcioAvatar de sigstore

    sigstore/fulcio

    859Voir sur GitHub↗

    Sigstore OIDC PKI

    Go
    Voir sur GitHub↗859
  • sigstore/rekorAvatar de sigstore

    sigstore/rekor

    1,168Voir sur GitHub↗

    Software Supply Chain Transparency Log

    Go
    Voir sur GitHub↗1,168
  • slsa-framework/slsaAvatar de slsa-framework

    slsa-framework/slsa

    1,881Voir sur GitHub↗

    Supply-chain Levels for Software Artifacts

    HTML
    Voir sur GitHub↗1,881
  • spectralops/preflightAvatar de spectralops

    spectralops/preflight

    157Voir sur GitHub↗

    preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.

    Go
    Voir sur GitHub↗157
  • step-security/harden-runnerAvatar de step-security

    step-security/harden-runner

    1,206Voir sur GitHub↗

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

    TypeScript
    Voir sur GitHub↗1,206
  • tektoncd/chainsAvatar de tektoncd

    tektoncd/chains

    271Voir sur GitHub↗

    Supply Chain Security in Tekton Pipelines

    Go
    Voir sur GitHub↗271
  • anchore/syftAvatar de anchore

    anchore/syft

    8,399Voir sur GitHub↗

    Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche

    Gocontainerscyclonedxdocker
    Voir sur GitHub↗8,399
  • xojs/xoAvatar de xojs

    xojs/xo

    7,977Voir sur GitHub↗

    xo is a zero-configuration linting tool for JavaScript and TypeScript. It functions as a wrapper for the ESLint engine, providing a set of strict default rules and static analysis to enforce professional coding standards without requiring manual configuration files. The tool distinguishes itself by providing a zero-config runtime that automatically determines parser settings and linting rules at execution time. It includes a code style formatter to standardize indentation and syntax across all project files. The project covers automated error correction and source code formatting to eliminat

    TypeScript
    Voir sur GitHub↗7,977