wg-securing-software-repos

OpenSSF Working Group on Securing Software Repositories (by ossf)

Wg-securing-software-repos Alternatives

Similar projects and alternatives to wg-securing-software-repos

ossf
wg-securing-software-repos
  1. warehouse

    The Python Package Index

  2. CodeRabbit

    CodeRabbit: AI Code Reviews for Developers. Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.

    CodeRabbit logo
  3. rubygems

    Library packaging and distribution for Ruby.

  4. RubyGems

    The Ruby community's gem hosting service.

  5. rfcs

    RubyGems + Bundler RFCs (by rubygems)

  6. gem-compare

    A RubyGems plugin that compares versions of the given gem

  7. rfcs

    RubyGems + Bundler RFCs (by Shopify)

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better wg-securing-software-repos alternative or higher similarity.

wg-securing-software-repos discussion

Log in or Post with

wg-securing-software-repos reviews and mentions

Posts with mentions or reviews of wg-securing-software-repos. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-06-13.
  • Making popular Ruby packages more secure
    6 projects | news.ycombinator.com | 13 Jun 2022
    RubyGems does have gem signing, but it's not widely used.

    There's a proposal for a new "one button" approach using sigstore[0].

    Other ecosystems are also looking at sigstore too, and a lot of us are cooperating in the OpenSSF Securing Software Repos WG [1]. Package signing is a regular topic of discussion and there are various efforts underway.

    Disclosure: I am involved with both of these.

    [0] https://github.com/rubygems/rubygems.org/pull/2944

    [1] https://github.com/ossf/wg-securing-software-repos

  • Unauthorized gem takeover for some gems
    7 projects | news.ycombinator.com | 7 May 2022
    In particular, check out the Securing Software Repos WG: https://github.com/ossf/wg-securing-software-repos

    So far folks have turned up from RubyGems, PyPI, NPM, Maven Central, Drupal and I'm probably forgotten someone.

Stats

Basic wg-securing-software-repos repo stats
2
103
6.0
6 months ago

Sponsored
CodeRabbit: AI Code Reviews for Developers
Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.
coderabbit.ai