awesome-repositories.com
Blog
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectDespreCum realizăm clasamentulPresăServer MCP
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
ossf avatar

ossf/scorecard

0
View on GitHub↗
5,527 stele·665 fork-uri·Go·Apache-2.0·4 vizualizăriscorecard.dev↗

Scorecard

Scorecard este un scanner de securitate open source și un instrument de analiză a lanțului de aprovizionare software care evaluează postura de securitate a proiectelor prin calcularea metricilor de risc bazate pe bune practici. Funcționează ca un dashboard de sănătate a securității, vizualizând lacunele de securitate prin scoruri și badge-uri pentru a ajuta mentenanții să identifice vulnerabilitățile.

Proiectul oferă un sistem pentru monitorizarea securității repository-ului printr-un auditor de securitate GitHub Action care alertează mentenanții atunci când scorurile de securitate scad. De asemenea, oferă un mecanism pentru ghidarea remedierii vulnerabilităților, mapând lacunele de securitate identificate la instrucțiuni prescriptive pentru îmbunătățirea practicilor de dezvoltare.

Instrumentul acoperă o suprafață largă de capabilități, inclusiv auditul de securitate open source, automatizarea securității CI/CD și analiza repository-urilor terțe pentru a evalua riscul înainte de integrare. Suportă diverse interfețe pentru interacțiune, inclusiv o interfață în linie de comandă pentru scanare și o interfață REST pentru preluarea metricilor de securitate precalculate.

Features

  • Open Source Security Scanners - Evaluates the security posture of open source projects by calculating risk metrics based on industry best practices.
  • Security Posture Checklists - Evaluates source code and build processes to generate an aggregate security score and risk level.
  • Security Auditors - Provides a GitHub Action that monitors repository changes and alerts maintainers when security scores drop.
  • CI/CD Security Metrics Automation - Integrates security health checks into CI pipelines to detect regressions and alert maintainers.
  • Open Source Security - Evaluates the security posture of open source projects by scanning code and build processes.
  • Security Guides - Provides specific prompts and instructions to resolve identified security gaps.
  • Repository Security Health Tracking - Tracks security scores over time using automated badges and reports to maintain project posture.
  • Remediation Guidance - Maps security failures to prescriptive instructions to help maintainers improve their project's security posture.
  • Software Supply Chain Security - Analyzes third party dependencies and repositories to assess risk in the software supply chain.
  • Third Party Dependency Risk Assessment - Scans third-party repositories to assess their security posture before they are added as dependencies.
  • Security Findings Visualizations - Renders detailed graphical security analyses to help users identify and resolve security gaps.
  • Visual Badges - Generates auto-updating visual badges for project documentation to represent security ratings.
  • Repository Content Scanning - Enables security analysis of target projects via a terminal interface using repository links.
  • CLI Scanning Interfaces - Provides a command line interface to execute security evaluations on target projects.
  • Security Analysis Dashboards - Visualizes security gaps through scores, badges, and remediation guidance via a dedicated reporting interface.
  • Security Monitoring - Integrates security scanning into version control workflows to issue alerts on repository changes.
  • Automated Security Scan Triggers - Automates security scans on every code commit through CI pipelines to alert maintainers of regressions.
  • GitHub Actions - Integrates security checks as a GitHub Action workflow step for immediate feedback on changes.
  • Security Automation Tools - Automates analysis of the security posture of open source projects.
  • Application Security - Provides security health metrics for open source projects.
  • Security and Vulnerability Scanning - Provides security health metrics for open source projects.

Istoric stele

Graficul istoricului de stele pentru ossf/scorecardGraficul istoricului de stele pentru ossf/scorecard

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Alternative open-source pentru Scorecard

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu Scorecard.
  • kubescape/kubescapeAvatar kubescape

    kubescape/kubescape

    11,489Vezi pe GitHub↗

    Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance risks. It functions as a comprehensive security suite incorporating a compliance scanner, a container image vulnerability scanner, an admission controller for policy enforcement, and a runtime security monitor. The platform distinguishes itself through runtime-aware vulnerability filtering, which maps libraries loaded in memory to determine if vulnerabilities are actually reachable. It also integrates with AI assistants via a Mo

    Gobest-practicedevopskubernetes
    Vezi pe GitHub↗11,489
  • github/advisory-databaseAvatar github

    github/advisory-database

    2,337Vezi pe GitHub↗

    The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and track security vulnerability data across diverse open source software ecosystems. It functions as a unified source of truth for security advisories, providing machine-readable records that help developers and automated tools identify and manage threats within their software supply chains. The platform distinguishes itself by utilizing a version-controlled, git-based storage model that relies on pull-request-driven workflows for community curation and verification. By enforcing a s

    Vezi pe GitHub↗2,337
  • lyft/cartographyAvatar lyft

    lyft/cartography

    3,926Vezi pe GitHub↗

    Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from diverse cloud, identity, and software-as-a-service providers to model complex relationships between resources, users, and security findings within a centralized graph database. By mapping these interdependencies, the platform enables organizations to gain visibility into their environment and identify potential security risks through graph traversal queries. The platform distinguishes itself through its ontology-based normalization and cross-platform entity correlation, which map he

    Python
    Vezi pe GitHub↗3,926
  • snyk/snykAvatar snyk

    snyk/snyk

    5,586Vezi pe GitHub↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    TypeScript
    Vezi pe GitHub↗5,586
Vezi toate cele 30 alternative pentru Scorecard→

Întrebări frecvente

Ce face ossf/scorecard?

Scorecard este un scanner de securitate open source și un instrument de analiză a lanțului de aprovizionare software care evaluează postura de securitate a proiectelor prin calcularea metricilor de risc bazate pe bune practici. Funcționează ca un dashboard de sănătate a securității, vizualizând lacunele de securitate prin scoruri și badge-uri pentru a ajuta mentenanții să identifice vulnerabilitățile.

Care sunt principalele funcționalități ale ossf/scorecard?

Principalele funcționalități ale ossf/scorecard sunt: Open Source Security Scanners, Security Posture Checklists, Security Auditors, CI/CD Security Metrics Automation, Open Source Security, Security Guides, Repository Security Health Tracking, Remediation Guidance.

Care sunt câteva alternative open-source pentru ossf/scorecard?

Alternativele open-source pentru ossf/scorecard includ: kubescape/kubescape — Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for… github/advisory-database — The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and… snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… lyft/cartography — Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… anchore/grype — Grype is a command-line security scanner designed to identify known vulnerabilities within container images,…