CycloneDX / gh-python-generate-sbomLinks
GitHub action to generate a CycloneDX SBOM for Python
☆14Updated last year
Alternatives and similar repositories for gh-python-generate-sbom
Users that are interested in gh-python-generate-sbom are comparing it to the libraries listed below
Sorting:
- Open Source Vulnerability schema.☆224Updated last week
- Advisory database for Python packages published on pypi.org☆316Updated last week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆111Updated 2 weeks ago
- Utility that provides an API platform for validating, querying and managing BOM data☆124Updated 2 weeks ago
- A BOM repository server for distributing CycloneDX BOMs☆85Updated 6 months ago
- Functionality and DataModels of OWASP CycloneDX for Python☆100Updated this week
- sbomasm: The Complete SBOM Management Toolkit☆100Updated last week
- DTrackAuditor is the python script to faciliate usage of DependencyTrack in the CI.☆11Updated 8 months ago
- The Auditree common fetchers, checks and harvest reports library.☆20Updated 2 years ago
- Publishes BOMs to Dependency-Track from GitHub Actions☆58Updated last year
- Examples of SPDX files for software combinations☆140Updated 2 months ago
- Check your Python environments for vulnerable Open Source packages with OSS Index or Sonatype Nexus Lifecycle.☆132Updated 7 months ago
- Machine-readable specification for the attestation of security-relevant data.☆71Updated 2 weeks ago
- Produce an Open Source Vulnerability JSON file based on information in an SPDX document☆65Updated last year
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆136Updated last month
- CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments☆350Updated this week
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆213Updated 3 months ago
- CVSS2/3/4 library with interactive calculator for Python 2 and Python 3☆115Updated 5 months ago
- GitHub Secret Scanning Auto Remediator (GSSAR)☆46Updated 2 weeks ago
- Generate VEX (Vulnerability Exploitability Exchange) CycloneDX documents☆24Updated last year
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆109Updated this week
- Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.☆76Updated last week
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆74Updated last year
- Enrich SBOMs with data from third party services☆213Updated last month
- OASIS CSAF TC: Supporting version control for Work Product artifacts developed by members of TC, including prose specifications and secon…☆204Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆237Updated last year
- Generate SBOMs with gh CLI☆197Updated 7 months ago
- A small utility that keeps your Git repositories from leaking secrets, skipping hooks, or quietly drifting out of compliance. It’s design…☆32Updated 2 months ago
- A place to systematically store software bill of materials (SBOM) documents.☆50Updated 2 years ago
- SPDX Merge tool☆48Updated 8 months ago