OpenChain-Project / SBOM-sg-SEPIALinks
The team at Bosch were working on a mapping of SPDX and CycloneDX on both property level (= syntax) and a semantic interpretation of the information. They wrote a schema that describes a bare minimum SBOM on semantic level, and a validator for this. This repo is to explore the work done.
☆15Updated 2 weeks ago
Alternatives and similar repositories for SBOM-sg-SEPIA
Users that are interested in SBOM-sg-SEPIA are comparing it to the libraries listed below
Sorting:
- Functionality and DataModels of OWASP CycloneDX for Python☆102Updated 2 weeks ago
- This repo realizes the idea that OSS compliance activities will be less expensive by applying OSS principles☆94Updated this week
- A small application which needs a better name and collects oss-license metadata and combines it☆32Updated 2 months ago
- Plain text version of the OSADL Open Source Policy Template: The Basis for License Compliance☆20Updated 3 years ago
- The model for the information captured in SPDX version 3 standard.☆97Updated 2 weeks ago
- This repo contains license and copyright analysis results of open source packages. It further contains other license compliance relevant …☆53Updated last week
- Eclipse Tractus-X Industry Core Hub [IC-Hub] - The KIT/Use Case Speedway☆17Updated last week
- The SCANOSS python package providing a simple, easy to consume library for interacting with SCANOSS APIs/Engine.☆38Updated this week
- Reference GitHub Workflows for SBOM generation from the CISA SBOM Generation Reference Implementation Tiger Team☆33Updated last week
- Utility that converts SBOM documents from CycloneDX to SPDX☆33Updated 2 years ago
- SW360 project☆219Updated last week
- Software Quality Management Tool☆43Updated last week
- PURL to CPE Relationship mapping project.☆110Updated this week
- This is the OpenChain Telco Work Group☆19Updated 2 months ago
- The Disclosure-CLI provides an easy way to access the public api of the FOSS Disclosure Portal. It is the recommended tool for external s…☆18Updated last month
- SW360 Antenna project☆22Updated 4 years ago
- A collection of software to connect TAP devices under Linux and Windows to the Vector SIL Kit☆11Updated last week
- Open Source License Compliance Checklists☆11Updated last year
- This repository contains the reference material related to the OpenChain Project☆104Updated last month
- CaPyCLI - Python scripts for software license compliance automation with SW360☆22Updated this week
- Documentation - Eclipse Leda provides a Yocto-based build setup for SDV.EDGE components☆20Updated 2 years ago
- A scalable server implementation of the OSS Review Toolkit.☆49Updated this week
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆267Updated this week
- Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.☆79Updated last week
- free and open source software license compatibility tool.☆50Updated 10 months ago
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆478Updated this week
- A Python library to parse, validate and create SPDX documents.☆233Updated 3 weeks ago
- Repository to store the code developed in the context of the Safety Architecture WG☆18Updated last year
- ☆37Updated last year
- Examples of SPDX files for software combinations☆142Updated 2 months ago