CycloneDX / sbom-combinerLinks
Lockheed Martin developed utility to combine multiple CycloneDX SBOMs
☆13Updated 2 years ago
Alternatives and similar repositories for sbom-combiner
Users that are interested in sbom-combiner are comparing it to the libraries listed below
Sorting:
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 11 months ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- vexctl is a tool to attest VEX impact statements☆45Updated 2 years ago
- ☆71Updated last month
- SBOM Explorer - Discover and pull public SBOMs☆20Updated 7 months ago
- ☆14Updated 2 years ago
- An SBOM query language and associated utilities☆55Updated last year
- ☆58Updated 3 years ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆33Updated 3 years ago
- sbomasm: The Complete SBOM Management Toolkit☆98Updated this week
- Lockheed Martin developed utility to compare two CycloneDX SBOMs☆19Updated 4 years ago
- Spinnaker pipelines as code☆19Updated 3 years ago
- AWS Signer Plugin for Notation☆17Updated 2 weeks ago
- To manage Docker Content Trust and Notary certificates☆13Updated this week
- ☆120Updated 8 months ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆41Updated last month
- Comparison of Chainguard Images to others☆20Updated this week
- ☆30Updated this week
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆45Updated 2 years ago
- A BOM repository server for distributing CycloneDX BOMs☆85Updated 6 months ago
- ☆102Updated last year
- Easily run Conftest, pull remote policies, surface the results, and obtain test metrics☆12Updated 3 months ago
- A tool to create, transform and attest VEX metadata☆170Updated this week
- Securing Alice's, Bob's and Carl's software supply chain using in-toto☆102Updated last month
- sigstore maven plugin☆19Updated last year
- Trust Dexter to ensure that all your images are pinned by digest for better security☆31Updated 2 years ago
- ☆51Updated last month
- Alcide Kubernetes Audit Log Analyzer - Alcide kAudit☆35Updated 4 years ago
- SBOM Search - Context aware search in SBOM repositories☆29Updated last month
- Slack alert bot for matching Github Audit Events☆10Updated last year