maven-lockfile

Lockfiles for Maven. Pin your dependencies. Build with integrity. (by chains-project)

Maven-lockfile Alternatives

Similar projects and alternatives to maven-lockfile

  1. vite

    913 maven-lockfile VS vite

    Next generation frontend tooling. It's fast!

  2. Stream

    Stream - Scalable APIs for Chat, Feeds, Moderation, & Video. Stream helps developers build engaging apps that scale to millions with performant and flexible Chat, Feeds, Moderation, and Video APIs and SDKs powered by a global edge network and enterprise-grade infrastructure.

    Stream logo
  3. opensnitch

    OpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch.

  4. checkout

    81 maven-lockfile VS checkout

    Action for checking out a repo

  5. scorecard

    OpenSSF Scorecard - Security health metrics for Open Source

  6. changed-files

    :octocat: Github action to retrieve all (added, copied, modified, deleted, renamed, type changed, unmerged, unknown) files and directories.

  7. crxviewer

    24 maven-lockfile VS crxviewer

    Add-on / web app to view the source code of Chrome / Firefox / Opera 15 extensions and zip files.

  8. harden-runner

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

  9. InfluxDB

    InfluxDB – Built for High-Performance Time Series Workloads. InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.

    InfluxDB logo
  10. npmgraph

    A tool for exploring NPM modules and dependencies

  11. vet

    Next Generation Software Composition Analysis (SCA) with Malicious Package Detection, Code Context & Policy as Code

  12. PRevent

    Prevent merging of malicious code in pull requests

  13. paths-filter

    Conditionally run actions based on files modified by PR, feature branch or pushed commits

  14. changed-files

    A patched clone tj-actions with the malicious commit reverted (by trmlabs)

  15. verify-changed-files

    :octocat: Github action to verify file changes that occur during the workflow execution.

  16. agentkit

    1 maven-lockfile VS agentkit

    Every AI Agent deserves a wallet. (by coinbase)

  17. gh-action-pypi-publish

    The blessed :octocat: GitHub Action, for publishing your :package: distribution files to PyPI, the tokenless way: https://github.com/marketplace/actions/pypi-publish

  18. npq

    5 maven-lockfile VS npq

    safely install npm packages by auditing them pre-install stage

  19. eas-cli

    5 maven-lockfile VS eas-cli

    Fastest way to build, submit, and update iOS and Android apps

  20. malicious-code-ruleset

    Focused malicious code detection ruleset, with a high protection-to-noise ratio

  21. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better maven-lockfile alternative or higher similarity.

maven-lockfile discussion

Log in or Post with

maven-lockfile reviews and mentions

Posts with mentions or reviews of maven-lockfile. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2025-03-14.
  • Popular GitHub Action tj-actions/changed-files is compromised
    35 projects | news.ycombinator.com | 14 Mar 2025
    It seems to me that pinning to a sha was not sufficient; the Renovate bot was updating actions referenced by sha.

    Example: https://github.com/chains-project/maven-lockfile/pull/1111/f...

    This appears to be governed by the `pinGitHubActionDigests` helper configured in `renovate.json`.

  • Maven-Lockfile
    1 project | /r/Maven | 18 Apr 2023
    I saw a thread here about why Maven does not have a [lockfile] and in the research group I am currently working we built one. It is hosted on GitHub; see chains-project/maven-lockfile: Lockfiles for Maven. Pin your dependencies. Build with integrity. (github.com). We provide a maven-plugin and a GitHub action for easy integration. Feedback welcome.

Stats

Basic maven-lockfile repo stats
4
44
9.6
9 days ago

Sponsored
Stream - Scalable APIs for Chat, Feeds, Moderation, & Video.
Stream helps developers build engaging apps that scale to millions with performant and flexible Chat, Feeds, Moderation, and Video APIs and SDKs powered by a global edge network and enterprise-grade infrastructure.
getstream.io

Did you know that Java is
the 8th most popular programming language
based on number of references?