Showing 25 of 25 projects
Upgrades your package.json dependencies to the latest versions while preserving existing semantic versioning policies.
A tool for signing and verifying container images and other artifacts using the Sigstore framework.
A static analysis tool that finds security vulnerabilities and misconfigurations in GitHub Actions workflows.
Automated security health metrics for open source projects, assessing security best practices and risks.
A Composer package that blocks installation of PHP dependencies with known security vulnerabilities.
A curated list of DevSecOps tools, resources, and training materials for integrating security into the development lifecycle.
Open-source supply chain security scanner that automatically detects vulnerabilities like Log4Shell in dependencies and notifies via GitHub pull requests.
A CI/CD security agent that monitors GitHub Actions runners for threats like network egress, file integrity, and process activity.
A CLI tool for real-time malicious package detection and software supply chain security across multiple ecosystems.
A security linter for npm and yarn lockfiles to detect malicious package injections and enforce trust policies.
Embed dependency information into Rust binaries for vulnerability auditing in production.
An ATT&CK-like threat matrix mapping adversary tactics and techniques specific to CI/CD pipeline security.
Open-source detection rules for identifying SolarWinds SunBurst backdoor activities and related vulnerabilities across multiple security tools.
A security-hardened container runtime for AI coding agents using Incus system containers with real-time threat detection and credential isolation.
A CI/CD framework powered by Nix for building secure and reproducible software supply chains.
A GitHub Action to upload and scan files for malware using VirusTotal's analysis engine.
A lightweight, single-binary artifact registry supporting Docker, Maven, npm, PyPI, Cargo, and Go with zero dependencies.
A framework for analyzing and defending against supply chain attacks targeting Software Development Lifecycle infrastructure.
A tool to verify scripts and executables by hash to prevent supply chain attacks.
A drop-in library for resumable downloads and streaming integrity verification of large files in the browser.
A research project inventorying RCE-by-design features and code execution risks in CI/CD pipeline tools.
A curated list of high-signal resources for Google Cloud Build, covering CI/CD, security, and modern delivery pipelines.
An open-source, modular framework to detect and prevent dependency confusion attacks across multiple package managers.
A security proxy that protects Docker daemon sockets by filtering API endpoint calls with configurable rules.
A Composer plugin that generates accurate CycloneDX Software Bill of Materials (SBOM) for PHP projects.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.