RedHatProductSecurity / osidbLinks
OSIDB — Open Security Issue Database
☆31Updated this week
Alternatives and similar repositories for osidb
Users that are interested in osidb are comparing it to the libraries listed below
Sorting:
- Component Registry (Corgi) aggregates component data across Red Hat's supported products, managed services, and internal product pipeline…☆17Updated 4 months ago
- RapiDAST enables simple, continuous and fully automated application security testing☆73Updated this week
- OpenControl Database☆11Updated 2 years ago
- ☆50Updated this week
- A tool to analyse the list of detected CVEs in the containers (usually created by static security scanner) and compare them to the Red Ha…☆24Updated 2 years ago
- Caching service for source code and external dependencies☆61Updated last month
- ☆29Updated last week
- ☆62Updated 10 months ago
- Utility that provides an API and CLI to identify licenses and legal terms☆50Updated last week
- Visualizer for GUAC☆28Updated last week
- Operator providing Kubernetes cluster compliance checks☆47Updated this week
- Repository of SBOMs generated by the syft SBOM generator tool, against a list of popular dockerhub container images.☆17Updated 8 months ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated 2 years ago
- Check SPDX SBOM for NTIA minimum elements☆63Updated last week
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆97Updated this week
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆92Updated 2 weeks ago
- A place to systematically store software bill of materials (SBOM) documents.☆46Updated 2 years ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆81Updated last week
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 4 months ago
- Format agnostic SBOM tooling☆107Updated last week
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- ☆44Updated this week
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆11Updated last week
- Examples of SPDX files for software combinations☆131Updated 3 weeks ago
- The model for the information captured in SPDX version 3 standard.☆84Updated 2 weeks ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆18Updated 3 weeks ago
- Go implementation of witness☆37Updated last week
- Search an SBOM for licenses and the packages they belong to☆92Updated this week
- Automating Compliance Tooling Project☆21Updated 3 years ago
- ☆20Updated this week