Santandersecurityresearch / cryptobom-forgeLinks
Tools and utilities needed to parse GitHub Multi-Repository Variant Analysis output
☆21Updated 3 weeks ago
Alternatives and similar repositories for cryptobom-forge
Users that are interested in cryptobom-forge are comparing it to the libraries listed below
Sorting:
- PQC Transition Tools Index☆33Updated 4 months ago
- This repository contains a SonarQube Plugin that detects cryptographic assets in source code and generates CBOM.☆35Updated last week
- A toolset for dealing with Cryptography Bill of Materials (CBOM)☆32Updated this week
- OWASP Foundation Web Respository☆17Updated last year
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆185Updated last year
- A reading list for software supply-chain security.☆363Updated 2 years ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆83Updated 2 weeks ago
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆89Updated this week
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆191Updated 3 months ago
- ☆116Updated this week
- OWASP Foundation web repository☆23Updated this week
- A community collection of security reviews of open source software components.☆95Updated last year
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆136Updated last year
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆325Updated 2 years ago
- StartLeft is an automation tool for generating Threat Models written in the Open Threat Model (OTM) format from a variety of different so…☆51Updated this week
- ☆25Updated last year
- Cryptography Bill of Materials☆69Updated 5 months ago
- OpenSSF Security Tooling Working Group☆311Updated last week
- Software Component Verification Standard (SCVS)☆148Updated 3 months ago
- Core model including reused documentation☆98Updated last month
- OpenVEX Specification☆155Updated last month
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆172Updated 7 months ago
- OWASP Foundation Web Respository☆18Updated last month
- Network Cryptography Monitor - using eBPF, written in python☆33Updated 3 weeks ago
- SBOM Assess - Evaluate SBOM quality and compliance☆220Updated last week
- Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data☆61Updated last year
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆196Updated 3 months ago
- ☆94Updated this week
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and o…☆75Updated 2 months ago
- Github action to generate BoM and upload to OWASP dependency track for vulnerability analysis☆42Updated 9 months ago