QMSTR / qmstrLinks
QMSTR compliance tool
☆32Updated 3 years ago
Alternatives and similar repositories for qmstr
Users that are interested in qmstr are comparing it to the libraries listed below
Sorting:
- container-inspector is a suite of analysis utilities and command line tools for Docker container images, their layers and how these relat…☆37Updated 8 months ago
- SPDX Tools☆143Updated last month
- Automating Compliance Tooling Project☆22Updated 3 years ago
- Hermeto is a CLI tool that prefetches your project dependencies to aid in making your container build process hermetic.☆26Updated this week
- Examples of SPDX files for software combinations☆139Updated 2 weeks ago
- A small application which needs a better name and collects oss-license metadata and combines it☆32Updated last week
- OSPO Landscape☆41Updated 2 weeks ago
- A specification for signing methods and formats used by Secure Systems Lab projects.☆88Updated 3 weeks ago
- Prospector permits automated collection of a wide range of metrics of open source projects useful in evaluating the project.☆66Updated 6 years ago
- ☆68Updated last year
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆111Updated this week
- Machine-readable specification for the attestation of security-relevant data.☆66Updated 2 months ago
- This repo realizes the idea that OSS compliance activities will be less expensive by applying OSS principles☆90Updated 3 weeks ago
- Example CLI project to demo API architecture and protobom library☆23Updated last week
- The Disclosure-CLI provides an easy way to access the public api of the FOSS Disclosure Portal. It is the recommended tool for external s…☆17Updated this week
- Publications done by Double Open.☆16Updated 5 years ago
- Utility library to parse, normalize and compare License expressions for Python using a boolean logic engine. For expressions using SPDX …☆70Updated 4 months ago
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆42Updated 2 years ago
- sbomasm: The Complete SBOM Management Toolkit☆94Updated last week
- ☆37Updated 10 months ago
- The System Package Data Exchange (SPDX) specification in Markdown and HTML formats.☆346Updated this week
- A light-weight app to audit and inventory large codebases for open source license compliance.☆69Updated this week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆33Updated 7 months ago
- Technical Advisory Council☆133Updated 2 weeks ago
- Enrich SBOMs with data from third party services☆201Updated 3 months ago
- Doc, wiki and organizational content for ClearlyDefined☆104Updated last month
- Securing Alice's, Bob's and Carl's software supply chain using in-toto☆100Updated last week
- Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.☆74Updated last week
- A proof-of-concept SLSA provenance generator for Jenkins☆24Updated last year
- material designed to help organizations meet the training and process requirements of the OpenChain Specification☆30Updated 3 years ago