awesome-repositories.com
博客
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to en/code-security

Open-source alternatives to Code Security

16 open-source projects similar to en/code-security, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Code Security alternative.

  • denysvuika/supply-chain-inspectorDenysVuika 的头像

    DenysVuika/supply-chain-inspector

    3在 GitHub 上查看↗

    A standalone, zero-dependency Node.js script for supply chain security analysis of npm dependencies.

    JavaScript
    在 GitHub 上查看↗3
  • aquasecurity/chain-benchaquasecurity 的头像

    aquasecurity/chain-bench

    774在 GitHub 上查看↗

    An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

    Go
    在 GitHub 上查看↗774
  • deislabs/ratifydeislabs 的头像

    deislabs/ratify

    303在 GitHub 上查看↗

    Artifact Ratification Framework (CNCF Sandbox)

    Go
    在 GitHub 上查看↗303
  • ellerbrock/typescript-badgesE

    ellerbrock/typescript-badges

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • grafeas/kritisgrafeas 的头像

    grafeas/kritis

    710在 GitHub 上查看↗

    Deploy-time Policy Enforcer for Kubernetes applications

    Go
    在 GitHub 上查看↗710
  • in-toto/attestationin-toto 的头像

    in-toto/attestation

    341在 GitHub 上查看↗

    in-toto Attestation Framework

    Rust
    在 GitHub 上查看↗341

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Find more with AI search
  • os-scar/overlayos-scar 的头像

    os-scar/overlay

    228在 GitHub 上查看↗

    Overlay

    JavaScript
    在 GitHub 上查看↗228
  • sigstore/cosignsigstore 的头像

    sigstore/cosign

    5,667在 GitHub 上查看↗

    Cosign is a tool for signing and verifying software artifacts, primarily those stored in OCI-compatible registries such as container images, Helm charts, SBOMs, and Tekton bundles. It supports keyless signing using ephemeral keys and short-lived certificates from the Sigstore public-good infrastructure, associating signatures with an OpenID Connect identity rather than a long-lived cryptographic key. The project provides multiple signing and verification methods, including private keys, key pairs stored in KMS providers like AWS KMS and Azure Key Vault, and hardware security keys. It can sign

    Go
    在 GitHub 上查看↗5,667
  • sigstore/fulciosigstore 的头像

    sigstore/fulcio

    859在 GitHub 上查看↗

    Sigstore OIDC PKI

    Go
    在 GitHub 上查看↗859
  • sigstore/rekorsigstore 的头像

    sigstore/rekor

    1,168在 GitHub 上查看↗

    Software Supply Chain Transparency Log

    Go
    在 GitHub 上查看↗1,168
  • slsa-framework/slsaslsa-framework 的头像

    slsa-framework/slsa

    1,881在 GitHub 上查看↗

    Supply-chain Levels for Software Artifacts

    HTML
    在 GitHub 上查看↗1,881
  • spectralops/preflightspectralops 的头像

    spectralops/preflight

    157在 GitHub 上查看↗

    preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.

    Go
    在 GitHub 上查看↗157
  • step-security/harden-runnerstep-security 的头像

    step-security/harden-runner

    1,206在 GitHub 上查看↗

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

    TypeScript
    在 GitHub 上查看↗1,206
  • tektoncd/chainstektoncd 的头像

    tektoncd/chains

    271在 GitHub 上查看↗

    Supply Chain Security in Tekton Pipelines

    Go
    在 GitHub 上查看↗271
  • anchore/syftanchore 的头像

    anchore/syft

    8,399在 GitHub 上查看↗

    Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche

    Gocontainerscyclonedxdocker
    在 GitHub 上查看↗8,399
  • xojs/xoxojs 的头像

    xojs/xo

    7,977在 GitHub 上查看↗

    xo is a zero-configuration linting tool for JavaScript and TypeScript. It functions as a wrapper for the ESLint engine, providing a set of strict default rules and static analysis to enforce professional coding standards without requiring manual configuration files. The tool distinguishes itself by providing a zero-config runtime that automatically determines parser settings and linting rules at execution time. It includes a code style formatter to standardize indentation and syntax across all project files. The project covers automated error correction and source code formatting to eliminat

    TypeScript
    在 GitHub 上查看↗7,977