QMSTR / qmstr
QMSTR compliance tool
☆32Updated 2 years ago
Alternatives and similar repositories for qmstr:
Users that are interested in qmstr are comparing it to the libraries listed below
- container-inspector is a suite of analysis utilities and command line tools for Docker container images, their layers and how these relat…☆37Updated last month
- Automating Compliance Tooling Project☆21Updated 3 years ago
- SPDX Tools☆136Updated last year
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆69Updated this week
- ☆35Updated 3 months ago
- OSPO Landscape☆36Updated last week
- Publications done by Double Open.☆16Updated 4 years ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆88Updated this week
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆42Updated last year
- A light-weight app to audit and inventory large codebases for open source license compliance.☆65Updated this week
- SPDX SBOM Landscape☆15Updated last year
- A small application which needs a better name and collects oss-license metadata and combines it☆31Updated last week
- A java api and command line tool for scanning, reporting and fixing a git repository's InnerSource Readiness based on a supplied specific…☆20Updated last year
- This repo realizes the idea that OSS compliance activities will be less expensive by applying OSS principles☆86Updated this week
- This repository stores meetings minutes for the SPDX project☆30Updated last week
- A Jenkins plugin to track steps and create in-toto link metadata☆11Updated 10 months ago
- ☆21Updated 5 months ago
- OSS License Open Data☆12Updated 5 years ago
- SW360 Antenna project☆22Updated 4 years ago
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆16Updated last week
- Examples of SPDX files for software combinations☆129Updated last week
- ☆62Updated 9 months ago
- This repo is for tracking activities that we work on during TODO Group Work Days☆15Updated 2 years ago
- Utility that provides an API and CLI to identify licenses and legal terms☆43Updated 10 months ago
- Utility that converts SBOM documents from CycloneDX to SPDX☆28Updated last year
- material designed to help organizations meet the training and process requirements of the OpenChain Specification☆30Updated 2 years ago
- SPDX 2.0 document creation and storage☆16Updated 2 years ago
- Find & pull public SBOMs☆18Updated 8 months ago
- Prospector permits automated collection of a wide range of metrics of open source projects useful in evaluating the project.☆66Updated 6 years ago
- The model for the information captured in SPDX version 3 standard.☆82Updated this week