OpenChain-Project / SBOM-sg-SEPIALinks
The team at Bosch were working on a mapping of SPDX and CycloneDX on both property level (= syntax) and a semantic interpretation of the information. They wrote a schema that describes a bare minimum SBOM on semantic level, and a validator for this. This repo is to explore the work done.
☆15Updated last week
Alternatives and similar repositories for SBOM-sg-SEPIA
Users that are interested in SBOM-sg-SEPIA are comparing it to the libraries listed below
Sorting:
- This repo contains license and copyright analysis results of open source packages. It further contains other license compliance relevant …☆53Updated this week
- The model for the information captured in SPDX version 3 standard.☆97Updated last week
- This is the OpenChain Telco Work Group☆19Updated 2 months ago
- This repo realizes the idea that OSS compliance activities will be less expensive by applying OSS principles☆93Updated this week
- Reference GitHub Workflows for SBOM generation from the CISA SBOM Generation Reference Implementation Tiger Team☆33Updated last week
- This repository contains the reference material related to the OpenChain Project☆104Updated last month
- ☆37Updated last year
- Repository of workplace for the OpenChain Japan Work Group(JWG)☆10Updated 3 years ago
- The SCANOSS python package providing a simple, easy to consume library for interacting with SCANOSS APIs/Engine.☆38Updated this week
- A small application which needs a better name and collects oss-license metadata and combines it☆32Updated 2 months ago
- Functionality and DataModels of OWASP CycloneDX for Python☆102Updated last week
- Utility that converts SBOM documents from CycloneDX to SPDX☆33Updated 2 years ago
- SW360 Antenna project☆22Updated 4 years ago
- Vector Bazel Rules and Toolchains☆14Updated last week
- CaPyCLI - Python scripts for software license compliance automation with SW360☆22Updated last week
- A collection of software to connect TAP devices under Linux and Windows to the Vector SIL Kit☆11Updated last week
- free and open source software license compatibility tool.☆50Updated 9 months ago
- Eclipse Tractus-X Industry Core Hub [IC-Hub] - The KIT/Use Case Speedway☆17Updated this week
- SW360 project☆214Updated this week
- Examples of SPDX files for software combinations☆141Updated 2 months ago
- PURL to CPE Relationship mapping project.☆109Updated last week
- Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.☆79Updated this week
- The Disclosure-CLI provides an easy way to access the public api of the FOSS Disclosure Portal. It is the recommended tool for external s…☆18Updated last month
- WARNING - Work in Progress - It is not Bug Free! Use with Caution. This repository contains Dockerfiles and accompanying scripts that all…☆13Updated 3 years ago
- Code examples for EB GUIDE☆11Updated 4 years ago
- OSS License Open Data☆12Updated 6 years ago
- FOSSLight Dependency Scanner☆35Updated last week
- Software Quality Management Tool☆43Updated this week
- The MobSTr dataset provides artifacts that demonstrate Model-based Safety Assurance and Traceability for a safety-critical automotive sys…☆10Updated 3 years ago
- Eclipse Leda - Self Update Agent (SUA)☆15Updated 2 years ago