代码库
The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
JavaScript
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
Python
cvecvssdevsecopshacktoberfestpythonsbomsbom-toolsecuritysecurity-automationsecurity-toolsswreposystem-toolsvulnerabilitiesvulnerability
Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, produce and use.
Cyber Reasoning Systems for Bug-Finding and Patching in Open Source Software
Python
OpenSSF Scorecard - Security health metrics for Open Source
Go
openssf-scorecardscorecard
GitHub App to set and enforce security policies
Go