PQCA / cbomkit
A toolset for dealing with Cryptography Bill of Materials (CBOM)
☆30Updated this week
Alternatives and similar repositories for cbomkit
Users that are interested in cbomkit are comparing it to the libraries listed below
Sorting:
- A tool for detecting cryptographic assets in container images and directories, and generating CBOMs.☆14Updated this week
- This repository contains a SonarQube Plugin that detects cryptographic assets in source code and generates CBOM.☆33Updated this week
- A standard API specification for exchanging supply chain artifacts and intelligence☆80Updated this week
- Cryptography Bill of Materials☆67Updated 3 months ago
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆78Updated 6 months ago
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- OpenVEX Specification☆150Updated last month
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆133Updated last year
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆207Updated 3 months ago
- sbomify is an SBOM management platform.☆24Updated this week
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- ☆82Updated this week
- Software Supply Chain Security Platform☆333Updated last week
- Incubating project for decoupling responsibilities from Dependency-Track's monolithic API server into separate, scalable services.☆70Updated this week
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆195Updated last month
- A BOM repository server for distributing CycloneDX BOMs☆77Updated last year
- PQC Transition Tools Index☆30Updated 2 months ago
- ☆25Updated last year
- Tools and utilities needed to parse GitHub Multi-Repository Variant Analysis output☆19Updated 7 months ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆94Updated last week
- in-toto is a framework to secure the software supply chain.☆70Updated 4 months ago
- A tool for preventing the installation of malicious PyPI and npm packages☆143Updated last week
- ☆62Updated 9 months ago
- VMClarity is a tool for agentless detection and management of Virtual Machine Software Bill Of Materials (SBOM) and vulnerabilities☆102Updated 7 months ago
- Generative and mutative fuzzer for Kubernetes admission controller chains by automatically parsing the cluster api specification.☆74Updated last year
- SecObserve is an open source vulnerability and license management system for software development teams and cloud environments. It suppor…☆133Updated this week
- Repository for on-going work as part of the AIBOM Tiger Team effort.☆21Updated 2 weeks ago
- Utility that provides an API platform for validating, querying and managing BOM data☆109Updated 3 weeks ago
- ☆177Updated 3 weeks ago
- ☆235Updated last week