CycloneDX / sbom-comparatorLinks
Lockheed Martin developed utility to compare two CycloneDX SBOMs
☆19Updated 4 years ago
Alternatives and similar repositories for sbom-comparator
Users that are interested in sbom-comparator are comparing it to the libraries listed below
Sorting:
- ☆119Updated 6 months ago
- Lockheed Martin developed utility to combine multiple CycloneDX SBOMs☆13Updated 2 years ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 8 months ago
- SBOM Explorer - Discover and pull public SBOMs☆20Updated 4 months ago
- List of SBOM Generation Tools☆27Updated 7 months ago
- A BOM repository server for distributing CycloneDX BOMs☆82Updated 3 months ago
- Open Policy Agent extension for Authzed SpiceDB☆21Updated last week
- Zanzibar style fine grained authorization☆19Updated this week
- A place to systematically store software bill of materials (SBOM) documents.☆47Updated 2 years ago
- Utility that provides an API platform for validating, querying and managing BOM data☆120Updated 3 weeks ago
- ☆102Updated last year
- Implementation of SCIM☆37Updated last year
- Generate a score for your sbom to understand if it will actually be useful.☆234Updated last year
- sigstore maven plugin☆18Updated last year
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated 2 years ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆102Updated this week
- A simple Java command-line utility to mirror the entire contents of VulnDB.☆48Updated 3 months ago
- Log4Shell CVE-2021-44228 mitigation tester☆16Updated 3 years ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data☆65Updated last year
- sbomasm: The Complete SBOM Management Toolkit☆89Updated last week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆104Updated last week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆33Updated 6 months ago
- Lockheed Martin developed utility to generate CycloneDX SBOMs for Linux distributions☆48Updated 2 weeks ago
- vexctl is a tool to attest VEX impact statements☆45Updated 2 years ago
- Specification for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆26Updated 2 months ago
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆96Updated this week
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆88Updated 2 weeks ago
- Repository for development of IDQL Policy Language☆14Updated 11 months ago