awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेसMCP सर्वर
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
ossf avatar

ossf/scorecard

0
View on GitHub↗
5,527 स्टार्स·665 फोर्क्स·Go·Apache-2.0·4 व्यूज़scorecard.dev↗

Scorecard

Scorecard is an open source security scanner and software supply chain analysis tool that evaluates the security posture of projects by calculating risk metrics based on best practices. It functions as a security health dashboard, visualizing security gaps through scores and badges to help maintainers identify vulnerabilities.

The project provides a system for monitoring repository security through a GitHub Action security auditor that alerts maintainers when security scores drop. It also offers a mechanism for vulnerability remediation guidance, mapping identified security gaps to prescriptive instructions for improving development practices.

The tool covers a broad capability surface including open source security auditing, CI/CD security automation, and the analysis of third party repositories to assess risk before integration. It supports various interfaces for interaction, including a command line interface for scanning and a REST interface for retrieving precalculated security metrics.

Features

  • Open Source Security Scanners - Evaluates the security posture of open source projects by calculating risk metrics based on industry best practices.
  • Security Posture Checklists - Evaluates source code and build processes to generate an aggregate security score and risk level.
  • Security Auditors - Provides a GitHub Action that monitors repository changes and alerts maintainers when security scores drop.
  • CI/CD Security Metrics Automation - Integrates security health checks into CI pipelines to detect regressions and alert maintainers.
  • Open Source Security - Evaluates the security posture of open source projects by scanning code and build processes.
  • Security Guides - Provides specific prompts and instructions to resolve identified security gaps.
  • Repository Security Health Tracking - Tracks security scores over time using automated badges and reports to maintain project posture.
  • Remediation Guidance - Maps security failures to prescriptive instructions to help maintainers improve their project's security posture.
  • Software Supply Chain Security - Analyzes third party dependencies and repositories to assess risk in the software supply chain.
  • Third Party Dependency Risk Assessment - Scans third-party repositories to assess their security posture before they are added as dependencies.
  • Security Findings Visualizations - Renders detailed graphical security analyses to help users identify and resolve security gaps.
  • Visual Badges - Generates auto-updating visual badges for project documentation to represent security ratings.
  • Repository Content Scanning - Enables security analysis of target projects via a terminal interface using repository links.
  • CLI Scanning Interfaces - Provides a command line interface to execute security evaluations on target projects.
  • Security Analysis Dashboards - Visualizes security gaps through scores, badges, and remediation guidance via a dedicated reporting interface.
  • Security Monitoring - Integrates security scanning into version control workflows to issue alerts on repository changes.
  • Automated Security Scan Triggers - Automates security scans on every code commit through CI pipelines to alert maintainers of regressions.
  • GitHub Actions - Integrates security checks as a GitHub Action workflow step for immediate feedback on changes.
  • Security Automation Tools - Automates analysis of the security posture of open source projects.
  • Application Security - Provides security health metrics for open source projects.
  • Security and Vulnerability Scanning - Provides security health metrics for open source projects.

स्टार हिस्ट्री

ossf/scorecard के लिए स्टार हिस्ट्री चार्टossf/scorecard के लिए स्टार हिस्ट्री चार्ट

AI सर्च

और अधिक बेहतरीन रिपॉजिटरी खोजें

अपनी ज़रूरत को सरल भाषा में बताएं — AI हजारों क्यूरेटेड ओपन-सोर्स प्रोजेक्ट्स को प्रासंगिकता के आधार पर रैंक करता है।

Start searching with AI

अक्सर पूछे जाने वाले प्रश्न

ossf/scorecard क्या करता है?

Scorecard is an open source security scanner and software supply chain analysis tool that evaluates the security posture of projects by calculating risk metrics based on best practices. It functions as a security health dashboard, visualizing security gaps through scores and badges to help maintainers identify vulnerabilities.

ossf/scorecard की मुख्य विशेषताएं क्या हैं?

ossf/scorecard की मुख्य विशेषताएं हैं: Open Source Security Scanners, Security Posture Checklists, Security Auditors, CI/CD Security Metrics Automation, Open Source Security, Security Guides, Repository Security Health Tracking, Remediation Guidance।

ossf/scorecard के कुछ ओपन-सोर्स विकल्प क्या हैं?

ossf/scorecard के ओपन-सोर्स विकल्पों में शामिल हैं: kubescape/kubescape — Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for… github/advisory-database — The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and… snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… lyft/cartography — Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… anchore/grype — Grype is a command-line security scanner designed to identify known vulnerabilities within container images,…

Scorecard के ओपन-सोर्स विकल्प

समान ओपन-सोर्स प्रोजेक्ट्स, जो Scorecard के साथ साझा की गई सुविधाओं के आधार पर रैंक किए गए हैं।
  • kubescape/kubescapekubescape का अवतार

    kubescape/kubescape

    11,489GitHub पर देखें↗

    Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance risks. It functions as a comprehensive security suite incorporating a compliance scanner, a container image vulnerability scanner, an admission controller for policy enforcement, and a runtime security monitor. The platform distinguishes itself through runtime-aware vulnerability filtering, which maps libraries loaded in memory to determine if vulnerabilities are actually reachable. It also integrates with AI assistants via a Mo

    Gobest-practicedevopskubernetes
    GitHub पर देखें↗11,489
  • github/advisory-databasegithub का अवतार

    github/advisory-database

    2,337GitHub पर देखें↗

    The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and track security vulnerability data across diverse open source software ecosystems. It functions as a unified source of truth for security advisories, providing machine-readable records that help developers and automated tools identify and manage threats within their software supply chains. The platform distinguishes itself by utilizing a version-controlled, git-based storage model that relies on pull-request-driven workflows for community curation and verification. By enforcing a s

    GitHub पर देखें↗2,337
  • lyft/cartographylyft का अवतार

    lyft/cartography

    3,926GitHub पर देखें↗

    Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from diverse cloud, identity, and software-as-a-service providers to model complex relationships between resources, users, and security findings within a centralized graph database. By mapping these interdependencies, the platform enables organizations to gain visibility into their environment and identify potential security risks through graph traversal queries. The platform distinguishes itself through its ontology-based normalization and cross-platform entity correlation, which map he

    Python
    GitHub पर देखें↗3,926
  • snyk/snyksnyk का अवतार

    snyk/snyk

    5,586GitHub पर देखें↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    TypeScript
    GitHub पर देखें↗5,586
Scorecard के सभी 30 विकल्प देखें→