RedHatProductSecurity / component-registry
Component Registry (Corgi) aggregates component data across Red Hat's supported products, managed services, and internal product pipeline services.
☆17Updated 4 months ago
Alternatives and similar repositories for component-registry
Users that are interested in component-registry are comparing it to the libraries listed below
Sorting:
- OSIDB — Open Security Issue Database☆30Updated this week
- RapiDAST enables simple, continuous and fully automated application security testing☆71Updated this week
- Check SPDX SBOM for NTIA minimum elements☆61Updated 2 weeks ago
- A tool to analyse the list of detected CVEs in the containers (usually created by static security scanner) and compare them to the Red Ha…☆24Updated 2 years ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆79Updated this week
- A Python library and command line interface for CVE Services.☆65Updated 2 months ago
- ☆100Updated 7 months ago
- The model for the information captured in SPDX version 3 standard.☆83Updated this week
- A taxonomy of all official CycloneDX property namespaces and names☆16Updated last month
- SBOM Edit - Conditional edits and merging of SBOMs☆69Updated this week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆91Updated 2 weeks ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆94Updated last week
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Updated 2 years ago
- OpenControl Database☆11Updated 2 years ago
- Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data☆59Updated last year
- ☆21Updated 6 months ago
- This repository stores meetings minutes for the SPDX project☆30Updated 2 weeks ago
- ☆20Updated last week
- TUF repository for Sigstore trust root☆103Updated this week
- OpenSSF Endusers Working Group☆28Updated last year
- Generate VEX (Vulnerability Exploitability Exchange) CycloneDX documents☆22Updated 3 months ago
- SBOM Explorer - Discover and pull public SBOMs☆18Updated this week
- Machine-readable specification for the attestation of security-relevant data.☆59Updated last week
- Repository of SBOMs generated by the syft SBOM generator tool, against a list of popular dockerhub container images.☆17Updated 7 months ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆182Updated last year
- Integration and release of Konflux-CI☆60Updated this week
- ☆62Updated 9 months ago
- Services for storing and searching information about software content and vulnerabilities☆51Updated this week
- A CLI tool for creating secure by design/default source repos.☆25Updated 9 months ago
- Example CLI project to demo API architecture and protobom library☆20Updated last week