CycloneDX / gh-python-generate-sbomLinks
GitHub action to generate a CycloneDX SBOM for Python
☆14Updated last year
Alternatives and similar repositories for gh-python-generate-sbom
Users that are interested in gh-python-generate-sbom are comparing it to the libraries listed below
Sorting:
- Advisory database for Python packages published on pypi.org☆317Updated 2 weeks ago
- A BOM repository server for distributing CycloneDX BOMs☆86Updated 7 months ago
- Check your Python environments for vulnerable Open Source packages with OSS Index or Sonatype Nexus Lifecycle.☆132Updated 2 weeks ago
- Open Source Vulnerability schema.☆230Updated this week
- CVSS2/3/4 library with interactive calculator for Python 2 and Python 3☆116Updated 6 months ago
- Utility that provides an API platform for validating, querying and managing BOM data☆124Updated last month
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆110Updated 2 weeks ago
- Functionality and DataModels of OWASP CycloneDX for Python☆102Updated last week
- Publishes BOMs to Dependency-Track from GitHub Actions☆58Updated last year
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆215Updated 3 months ago
- Produce an Open Source Vulnerability JSON file based on information in an SPDX document☆65Updated last year
- CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments☆356Updated last week
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆136Updated last week
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers…☆135Updated 2 weeks ago
- Enrich SBOMs with data from third party services☆214Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆237Updated last year
- Python Faker provider for security related data☆41Updated 5 months ago
- Machine-readable specification for the attestation of security-relevant data.☆72Updated this week
- Examples of SPDX files for software combinations☆142Updated 2 months ago
- github action to run the bandit security linter☆15Updated 2 weeks ago
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆74Updated last year
- Optimize the utilization of GHAS licenses in an enterprise (or organization)☆15Updated 3 months ago
- Global Security Database☆318Updated last year
- OASIS CSAF TC: Supporting version control for Work Product artifacts developed by members of TC, including prose specifications and secon…☆206Updated last week
- The SCANOSS SBOM Workbench graphical user interface to scan and audit your source code.☆59Updated last week
- A standard API specification for exchanging supply chain artifacts and intelligence☆97Updated last week
- Lockheed Martin developed utility to generate CycloneDX SBOMs for Linux distributions☆50Updated 2 months ago
- A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain☆97Updated 11 months ago
- sbomasm: The Complete SBOM Management Toolkit☆101Updated this week
- Generate SBOMs with gh CLI☆198Updated 8 months ago