awesome-repositories.com
Blog
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
ossf avatar

ossf/scorecard

0
View on GitHub↗
5,527 stars·665 forks·Go·Apache-2.0·4 vuesscorecard.dev↗

Scorecard

Scorecard est un scanner de sécurité open source et un outil d'analyse de la chaîne d'approvisionnement logicielle qui évalue la posture de sécurité des projets en calculant des métriques de risque basées sur les meilleures pratiques. Il fonctionne comme un tableau de bord de santé de sécurité, visualisant les failles de sécurité via des scores et des badges pour aider les mainteneurs à identifier les vulnérabilités.

Le projet fournit un système pour surveiller la sécurité des dépôts via un auditeur de sécurité GitHub Action qui alerte les mainteneurs lorsque les scores de sécurité chutent. Il offre également un mécanisme de guidage pour la remédiation des vulnérabilités, mappant les failles de sécurité identifiées à des instructions prescriptives pour améliorer les pratiques de développement.

L'outil couvre une large surface de capacités, notamment l'audit de sécurité open source, l'automatisation de la sécurité CI/CD et l'analyse de dépôts tiers pour évaluer le risque avant intégration. Il prend en charge diverses interfaces pour l'interaction, incluant une interface en ligne de commande pour le scan et une interface REST pour récupérer des métriques de sécurité précalculées.

Features

  • Open Source Security Scanners - Evaluates the security posture of open source projects by calculating risk metrics based on industry best practices.
  • Security Posture Checklists - Evaluates source code and build processes to generate an aggregate security score and risk level.
  • Security Auditors - Provides a GitHub Action that monitors repository changes and alerts maintainers when security scores drop.
  • CI/CD Security Metrics Automation - Integrates security health checks into CI pipelines to detect regressions and alert maintainers.
  • Open Source Security - Evaluates the security posture of open source projects by scanning code and build processes.
  • Security Guides - Provides specific prompts and instructions to resolve identified security gaps.
  • Repository Security Health Tracking - Tracks security scores over time using automated badges and reports to maintain project posture.
  • Remediation Guidance - Maps security failures to prescriptive instructions to help maintainers improve their project's security posture.
  • Software Supply Chain Security - Analyzes third party dependencies and repositories to assess risk in the software supply chain.
  • Third Party Dependency Risk Assessment - Scans third-party repositories to assess their security posture before they are added as dependencies.
  • Security Findings Visualizations - Renders detailed graphical security analyses to help users identify and resolve security gaps.
  • Visual Badges - Generates auto-updating visual badges for project documentation to represent security ratings.
  • Repository Content Scanning - Enables security analysis of target projects via a terminal interface using repository links.
  • CLI Scanning Interfaces - Provides a command line interface to execute security evaluations on target projects.
  • Security Analysis Dashboards - Visualizes security gaps through scores, badges, and remediation guidance via a dedicated reporting interface.
  • Security Monitoring - Integrates security scanning into version control workflows to issue alerts on repository changes.
  • Automated Security Scan Triggers - Automates security scans on every code commit through CI pipelines to alert maintainers of regressions.
  • GitHub Actions - Integrates security checks as a GitHub Action workflow step for immediate feedback on changes.
  • Security Automation Tools - Automates analysis of the security posture of open source projects.
  • Application Security - Provides security health metrics for open source projects.
  • Security and Vulnerability Scanning - Provides security health metrics for open source projects.

Historique des stars

Graphique de l'historique des stars pour ossf/scorecardGraphique de l'historique des stars pour ossf/scorecard

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Start searching with AI

Questions fréquentes

Que fait ossf/scorecard ?

Scorecard est un scanner de sécurité open source et un outil d'analyse de la chaîne d'approvisionnement logicielle qui évalue la posture de sécurité des projets en calculant des métriques de risque basées sur les meilleures pratiques. Il fonctionne comme un tableau de bord de santé de sécurité, visualisant les failles de sécurité via des scores et des badges pour aider les mainteneurs à identifier les vulnérabilités.

Quelles sont les fonctionnalités principales de ossf/scorecard ?

Les fonctionnalités principales de ossf/scorecard sont : Open Source Security Scanners, Security Posture Checklists, Security Auditors, CI/CD Security Metrics Automation, Open Source Security, Security Guides, Repository Security Health Tracking, Remediation Guidance.

Quelles sont les alternatives open-source à ossf/scorecard ?

Les alternatives open-source à ossf/scorecard incluent : kubescape/kubescape — Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for… github/advisory-database — The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and… snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… lyft/cartography — Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… anchore/grype — Grype is a command-line security scanner designed to identify known vulnerabilities within container images,…

Alternatives open source à Scorecard

Projets open source similaires, classés selon le nombre de fonctionnalités partagées avec Scorecard.
  • kubescape/kubescapeAvatar de kubescape

    kubescape/kubescape

    11,489Voir sur GitHub↗

    Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance risks. It functions as a comprehensive security suite incorporating a compliance scanner, a container image vulnerability scanner, an admission controller for policy enforcement, and a runtime security monitor. The platform distinguishes itself through runtime-aware vulnerability filtering, which maps libraries loaded in memory to determine if vulnerabilities are actually reachable. It also integrates with AI assistants via a Mo

    Gobest-practicedevopskubernetes
    Voir sur GitHub↗11,489
  • github/advisory-databaseAvatar de github

    github/advisory-database

    2,337Voir sur GitHub↗

    The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and track security vulnerability data across diverse open source software ecosystems. It functions as a unified source of truth for security advisories, providing machine-readable records that help developers and automated tools identify and manage threats within their software supply chains. The platform distinguishes itself by utilizing a version-controlled, git-based storage model that relies on pull-request-driven workflows for community curation and verification. By enforcing a s

    Voir sur GitHub↗2,337
  • lyft/cartographyAvatar de lyft

    lyft/cartography

    3,926Voir sur GitHub↗

    Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from diverse cloud, identity, and software-as-a-service providers to model complex relationships between resources, users, and security findings within a centralized graph database. By mapping these interdependencies, the platform enables organizations to gain visibility into their environment and identify potential security risks through graph traversal queries. The platform distinguishes itself through its ontology-based normalization and cross-platform entity correlation, which map he

    Python
    Voir sur GitHub↗3,926
  • snyk/snykAvatar de snyk

    snyk/snyk

    5,586Voir sur GitHub↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    TypeScript
    Voir sur GitHub↗5,586
  • Voir les 30 alternatives à Scorecard→