Skip to content
View travi's full-sized avatar

Block or report travi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Supply Chain

22 repositories

Supply-chain Levels for Software Artifacts

Shell 1,685 242 Updated Jun 26, 2025

Utility for bulk image, license, package, and vulnerability discovery in containerize workloads on GCP. Includes CLI and Service with custom metrics and BigQuery data exports.

Go 14 2 Updated Feb 15, 2024

Generate a score for your sbom to understand if it will actually be useful.

Go 230 24 Updated Aug 13, 2024

A TypeScript library for creating dependency snapshots.

TypeScript 48 15 Updated Jun 30, 2025

Generate CycloneDX Software Bill of Materials (SBOM) from webpack bundles at compile time.

JavaScript 26 9 Updated Jun 30, 2025

A suite of tools to automate software compliance checks.

Kotlin 1,773 341 Updated Jul 1, 2025

The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.

C# 1,831 167 Updated Jul 1, 2025

GitHub CLI extension for generating a report on repository dependencies.

Go 52 4 Updated Sep 18, 2023

GitHub Advanced Security Policy as Code

Python 84 20 Updated Jun 30, 2025

Verify provenance from SLSA compliant builders

Go 269 56 Updated Jun 27, 2025

GUAC aggregates software security metadata into a high fidelity graph database.

Go 1,378 187 Updated Jul 1, 2025

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

TypeScript 840 72 Updated Jul 1, 2025

Keyless Git signing using Sigstore

Go 1,003 69 Updated Jun 30, 2025

A GitHub Action for detecting vulnerable dependencies and invalid licenses in your PRs

TypeScript 698 129 Updated Jun 23, 2025

Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.

JavaScript 91 23 Updated Jun 30, 2025

An SBOM query language and associated utilities

Go 54 4 Updated Jan 22, 2024

Enrich SBOMs with data from third party services

Go 177 27 Updated Apr 2, 2025

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

Go 571 49 Updated Mar 31, 2025

A draft standard for communicating a cryptographic record of build inputs for software artifacts.

26 3 Updated Apr 17, 2025

Action for generating SBOM attestations for workflow artifacts

TypeScript 31 4 Updated Jun 30, 2025

Create SBOMs in CycloneDX format for your Vite or Rollup projects with ease

TypeScript 13 3 Updated Jun 23, 2025

This is the GitHub repo of the OpenChain SBOM Study Group

10 2 Updated Jun 13, 2025