vet VS maven-lockfile

Compare vet vs maven-lockfile and see what are their differences.

vet

Next Generation Software Composition Analysis (SCA) with Malicious Package Detection, Code Context & Policy as Code (by safedep)

maven-lockfile

Lockfiles for Maven. Pin your dependencies. Build with integrity. (by chains-project)
Stream - Scalable APIs for Chat, Feeds, Moderation, & Video.
Stream helps developers build engaging apps that scale to millions with performant and flexible Chat, Feeds, Moderation, and Video APIs and SDKs powered by a global edge network and enterprise-grade infrastructure.
getstream.io
featured
InfluxDB – Built for High-Performance Time Series Workloads
InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.
www.influxdata.com
featured
vet maven-lockfile
17 4
523 44
25.6% -
9.3 9.6
4 days ago 4 days ago
Go Java
Apache License 2.0 MIT License
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

vet

Posts with mentions or reviews of vet. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2025-06-29.

maven-lockfile

Posts with mentions or reviews of maven-lockfile. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2025-03-14.
  • Popular GitHub Action tj-actions/changed-files is compromised
    35 projects | news.ycombinator.com | 14 Mar 2025
    It seems to me that pinning to a sha was not sufficient; the Renovate bot was updating actions referenced by sha.

    Example: https://github.com/chains-project/maven-lockfile/pull/1111/f...

    This appears to be governed by the `pinGitHubActionDigests` helper configured in `renovate.json`.

  • Maven-Lockfile
    1 project | /r/Maven | 18 Apr 2023
    I saw a thread here about why Maven does not have a [lockfile] and in the research group I am currently working we built one. It is hosted on GitHub; see chains-project/maven-lockfile: Lockfiles for Maven. Pin your dependencies. Build with integrity. (github.com). We provide a maven-plugin and a GitHub action for easy integration. Feedback welcome.

What are some alternatives?

When comparing vet and maven-lockfile you can also consider the following projects:

solarsploit - Red team tool that emulates the SolarWinds CI compromise attack vector.

verify-changed-files - :octocat: Github action to verify file changes that occur during the workflow execution.

cnspec - An open source, cloud-native security to protect everything from build to runtime

PRevent - Prevent merging of malicious code in pull requests

scorecard - OpenSSF Scorecard - Security health metrics for Open Source

changed-files - A patched clone tj-actions with the malicious commit reverted

Stream - Scalable APIs for Chat, Feeds, Moderation, & Video.
Stream helps developers build engaging apps that scale to millions with performant and flexible Chat, Feeds, Moderation, and Video APIs and SDKs powered by a global edge network and enterprise-grade infrastructure.
getstream.io
featured
InfluxDB – Built for High-Performance Time Series Workloads
InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.
www.influxdata.com
featured