CycloneDX / cyclonedx-javascript-library
Core functionality of OWASP CycloneDX for JavaScript (Node.js or WebBrowser) written in TypeScript.
☆15Updated last week
Alternatives and similar repositories for cyclonedx-javascript-library:
Users that are interested in cyclonedx-javascript-library are comparing it to the libraries listed below
- GitHub action to generate a CycloneDX SBOM for Node.js☆21Updated last week
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js Yarn projects.☆21Updated this week
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆124Updated 2 months ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆77Updated this week
- A curated list of awesome Cedar related tools and articles.☆53Updated 2 months ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆32Updated 6 months ago
- Utility that provides an API and CLI to identify licenses and legal terms☆43Updated 7 months ago
- A BOM repository server for distributing CycloneDX BOMs☆75Updated 10 months ago
- A draft standard for communicating a cryptographic record of build inputs for software artifacts.☆23Updated 3 months ago
- ☆12Updated 4 months ago
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆27Updated 7 months ago
- An OPAL custom data fetcher to bring authorization state from Postgres☆21Updated 7 months ago
- Enrich SBOMs with data from third party services☆151Updated last week
- Github Action implementation of SLSA Provenance Generation☆47Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆224Updated 5 months ago
- ☆31Updated 2 months ago
- SPDX Merge tool☆39Updated 4 months ago
- Node.JS Express middleware for working with the Open Policy Agent☆54Updated last year
- in-toto is a framework to secure the software supply chain.☆70Updated last week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆78Updated this week
- A tool to check the security settings of Github Organizations.☆70Updated last year
- Compare vulnerability scanners results (to make them better!)☆16Updated this week
- [GitHub] A Command Line ToolKit for GitHub Security Alert.☆26Updated 2 months ago
- Measure release insights and recommendations for open-source dependencies. Note: this project is archived.☆11Updated 2 years ago
- Service Control Policies that have been Latacora recommended all wrapped up in terraform that is easy to attach to an OU.☆22Updated 7 months ago
- Stupid scaffolding: copies an entire directory with variable substitution☆20Updated this week
- Generate SBOMs with gh CLI☆175Updated 3 months ago
- ☆22Updated this week
- Agile Threat Modeling as Code☆13Updated 2 years ago
- Code-signing for npm packages☆161Updated this week