Santandersecurityresearch / cryptobom-forge
Tools and utilities needed to parse GitHub Multi-Repository Variant Analysis output
☆15Updated 3 months ago
Alternatives and similar repositories for cryptobom-forge:
Users that are interested in cryptobom-forge are comparing it to the libraries listed below
- This repository contains a SonarQube Plugin that detects cryptographic assets in source code and generates CBOM.☆29Updated this week
- A standard API specification for exchanging supply chain artifacts and intelligence☆68Updated last month
- A toolset for dealing with Cryptography Bill of Materials (CBOM)☆17Updated this week
- Cryptography Bill of Materials☆61Updated 4 months ago
- Potential WG on Artificial Intelligence and Machine Learning (AI/ML)☆59Updated 3 months ago
- A community collection of security reviews of open source software components.☆93Updated 11 months ago
- Format agnostic SBOM tooling☆96Updated this week
- A CLI tool for creating secure by design/default source repos.☆25Updated 6 months ago
- ☆47Updated this week
- ☆100Updated 4 months ago
- OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Is…☆56Updated 2 weeks ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆84Updated this week
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- OpenVEX Specification☆140Updated 6 months ago
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆130Updated last year
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆32Updated last year
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- A tool to create, transform and attest VEX metadata☆126Updated this week
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆178Updated 11 months ago
- OWASP Foundation Web Respository☆10Updated last year
- Technical Advisory Council☆115Updated this week
- Takes a software bill of materials and outputs provenance, and activity data from trustypkg.dev☆11Updated 3 months ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis tool☆39Updated last year
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆79Updated this week
- ☆229Updated this week
- General sigstore community repo☆40Updated 2 weeks ago
- StartLeft is an automation tool for generating Threat Models written in the Open Threat Model (OTM) format from a variety of different so…☆49Updated 2 weeks ago
- OWASP Foundation Web Respository☆27Updated 5 months ago