anchore / cve-data-enrichment
☆15Updated this week
Alternatives and similar repositories for cve-data-enrichment
Users that are interested in cve-data-enrichment are comparing it to the libraries listed below
Sorting:
- ☆47Updated last week
- Compare vulnerability scanners results (to make them better!)☆16Updated 3 weeks ago
- Library to ingest and generate VEX documents☆15Updated 3 months ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆94Updated last week
- A place to systematically store software bill of materials (SBOM) documents.☆46Updated last year
- ☆48Updated this week
- Automate vulnerability triage which prioritizes remediation over discovery☆18Updated this week
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated 2 years ago
- Takes a software bill of materials and outputs provenance, and activity data from trustypkg.dev☆11Updated 7 months ago
- Scan GitHub Actions Workflow logs for IOCs☆15Updated this week
- A tool to check the security settings of Github Organizations.☆71Updated last year
- A standard API specification for exchanging supply chain artifacts and intelligence☆79Updated this week
- Global Security Database Tools☆42Updated last year
- ☆15Updated 3 years ago
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆79Updated 6 months ago
- Global Security Database Project☆28Updated 2 years ago
- Exploit Prediction Scoring System (EPSS)☆25Updated 2 years ago
- vexctl is a tool to attest VEX impact statements☆44Updated 2 years ago
- Format agnostic SBOM tooling☆106Updated this week
- Python implementation of Stakeholder-Specific Vulnerability Categorization (SSVC)☆21Updated 5 months ago
- OWASP Foundation Web Respository☆28Updated 8 months ago
- Machine-readable specification for the attestation of security-relevant data.☆59Updated last week
- Decision trees generated via Graphviz to inform pragmatic threat modelling.☆11Updated 4 years ago
- Maturity Model Collaborative project☆15Updated 2 years ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- A community collection of security reviews of open source software components.☆93Updated last year
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆11Updated 2 months ago
- DefectDojo Community Content☆18Updated 7 months ago
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Updated last year
- Enrich SBOMs with data from third party services☆172Updated last month