SAP / fosstars-rating-core
A framework for defining ratings for open source projects. In particular, the framework offers a security rating for open source projects that may be used to assess the security risk that comes with open source components.
☆61Updated last month
Alternatives and similar repositories for fosstars-rating-core:
Users that are interested in fosstars-rating-core are comparing it to the libraries listed below
- This repo realizes the idea that OSS compliance activities will be less expensive by applying OSS principles☆83Updated this week
- Publications done by Double Open.☆16Updated 4 years ago
- Check SPDX SBOM for NTIA minimum elements☆60Updated 2 weeks ago
- A taxonomy of all official CycloneDX property namespaces and names☆15Updated this week
- A light-weight app to audit and inventory large codebases for open source license compliance.☆61Updated this week
- OpenSSF Endusers Working Group☆28Updated 11 months ago
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆62Updated last week
- ☆113Updated 8 months ago
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆86Updated this week
- OSS License Open Data☆12Updated 5 years ago
- Utility that converts SBOM documents from CycloneDX to SPDX☆29Updated last year
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆183Updated this week
- A BOM repository server for distributing CycloneDX BOMs☆75Updated 11 months ago
- Utility that provides an API platform for validating, querying and managing BOM data☆104Updated 3 months ago
- A small application which needs a better name and collects oss-license metadata and combines it☆31Updated 2 weeks ago
- Service to scan licenses from source code☆12Updated last year
- Automating Compliance Tooling Project☆20Updated 3 years ago
- Examples of SPDX files for software combinations☆127Updated 3 weeks ago
- A scalable server implementation of the OSS Review Toolkit.☆27Updated this week
- ☆100Updated 4 months ago
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆193Updated 2 months ago
- Utility that provides an API and CLI to identify licenses and legal terms☆43Updated 8 months ago
- PURL to CPE Relationship mapping project.☆82Updated this week
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Updated last year
- Plugin for supporting SPDX in a Maven build.☆52Updated 2 weeks ago
- Software Component Verification Standard (SCVS)☆140Updated 10 months ago
- SW360 Antenna project☆22Updated 3 years ago
- SPDX Tools☆133Updated last year
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and o…☆75Updated last month
- Incubating project for decoupling responsibilities from Dependency-Track's monolithic API server into separate, scalable services.☆66Updated this week