Skip to content
View travi's full-sized avatar

Block or report travi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Supply Chain

22 repositories

Supply-chain Levels for Software Artifacts

Shell 1,613 233 Updated Feb 11, 2025

Utility for bulk image, license, package, and vulnerability discovery in containerize workloads on GCP. Includes CLI and Service with custom metrics and BigQuery data exports.

Go 14 3 Updated Feb 15, 2024

Generate a score for your sbom to understand if it will actually be useful.

Go 226 24 Updated Aug 13, 2024

A TypeScript library for creating dependency snapshots.

TypeScript 46 13 Updated Mar 7, 2025

Generate CycloneDX Software Bill of Materials (SBOM) from webpack bundles at compile time.

TypeScript 26 9 Updated Mar 8, 2025

A suite of tools to automate software compliance checks.

Kotlin 1,686 322 Updated Mar 7, 2025

The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.

C# 1,725 146 Updated Mar 8, 2025

GitHub CLI extension for generating a report on repository dependencies.

Go 50 3 Updated Sep 18, 2023

GitHub Advanced Security Policy as Code

Python 81 18 Updated Mar 3, 2025

Verify provenance from SLSA compliant builders

Go 248 52 Updated Feb 27, 2025

GUAC aggregates software security metadata into a high fidelity graph database.

Go 1,334 186 Updated Mar 7, 2025

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

TypeScript 680 59 Updated Mar 9, 2025

Keyless Git signing using Sigstore

Go 972 66 Updated Mar 3, 2025

A GitHub Action for detecting vulnerable dependencies and invalid licenses in your PRs

TypeScript 654 121 Updated Mar 7, 2025

Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.

JavaScript 79 22 Updated Mar 8, 2025

An SBOM query language and associated utilities

Go 54 3 Updated Jan 22, 2024

Enrich SBOMs with data from third party services

Go 161 23 Updated Feb 10, 2025

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

Go 548 44 Updated Mar 3, 2025

A draft standard for communicating a cryptographic record of build inputs for software artifacts.

23 3 Updated Feb 12, 2025

Action for generating SBOM attestations for workflow artifacts

TypeScript 25 3 Updated Mar 3, 2025

Create SBOMs in CycloneDX format for your Vite or Rollup projects with ease

TypeScript 9 3 Updated Mar 6, 2025

This is the GitHub repo of the OpenChain SBOM Study Group

9 2 Updated Feb 3, 2025