Quobis / action-owasp-dependecy-track-checkLinks
Github action to generate BoM and upload to OWASP dependency track for vulnerability analysis
☆48Updated last year
Alternatives and similar repositories for action-owasp-dependecy-track-check
Users that are interested in action-owasp-dependecy-track-check are comparing it to the libraries listed below
Sorting:
- Publishes BOMs to Dependency-Track from GitHub Actions☆56Updated last year
- Examples of integrating the Snyk CLI into a CI/CD system☆100Updated 10 months ago
- Generate a score for your sbom to understand if it will actually be useful.☆234Updated last year
- Enrich SBOMs with data from third party services☆196Updated 2 months ago
- ☆124Updated this week
- Count distinct contributor of Snyk watched repos across several SCM☆32Updated 2 months ago
- GitHub Advanced Security Policy as Code☆90Updated 2 weeks ago
- GitHub Action for creating software bill of materials using Syft.☆206Updated last week
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆244Updated last week
- boostsecurityio/poutine☆341Updated last week
- Generate SBOMs with gh CLI☆195Updated 5 months ago
- Github action to run dependency check☆84Updated 4 months ago
- A BOM repository server for distributing CycloneDX BOMs☆84Updated 4 months ago
- SecObserve is an open source vulnerability and license management system for software development teams and cloud environments. It suppor…☆188Updated last week
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆215Updated 5 months ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆498Updated last week
- Software Component Verification Standard (SCVS)☆150Updated 7 months ago
- GitHub Action to generate GitHub Advanced Security (GHAS) metrics report☆18Updated 9 months ago
- Software Supply Chain Security Platform☆355Updated this week
- The security workflow engine!☆125Updated 2 weeks ago
- A tool to check the security settings of Github Organizations.☆72Updated 2 years ago
- A utility to (re-)import findings and language data into DefectDojo☆43Updated last year
- ⚡️Snyk API powered import tool to help you automate & monitor a large scale import into Snyk organizations. Designed for onboarding with …☆43Updated this week
- ☆543Updated last week
- OWASP Foundation Web Respository☆99Updated 3 weeks ago
- NextJS-based single-page application for completing and reviewing SAMM assessments☆77Updated 2 years ago
- GitHub action to generate a CycloneDX SBOM for .NET☆12Updated 3 months ago
- Evaluate source control (GitHub) security posture☆251Updated 2 years ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆88Updated 3 weeks ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆190Updated last year