anchore / vulnerability-data-tools
☆12Updated this week
Related projects ⓘ
Alternatives and complementary repositories for vulnerability-data-tools
- ☆46Updated this week
- Stakeholder-Specific Vulnerability Categorization☆128Updated this week
- OASIS CSAF TC: Supporting version control for Work Product artifacts developed by members of TC, including prose specifications and secon…☆148Updated this week
- A standard API specification for exchanging supply chain artifacts and intelligence☆56Updated this week
- OpenVEX Specification☆130Updated 4 months ago
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆180Updated 3 months ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆70Updated last month
- Exploit Prediction Scoring System (EPSS)☆23Updated 2 years ago
- This project aims to standardize the representation and management of EOL and EOS product information across the industry.☆25Updated 8 months ago
- Secvisogram is a web tool for creating and editing security advisories in the CSAF 2.0 format☆19Updated 2 months ago
- ☆101Updated last month
- The model for the information captured in SPDX version 3 standard.☆70Updated 2 weeks ago
- Cryptography Bill of Materials☆56Updated last month
- Potential WG on Artificial Intelligence and Machine Learning (AI/ML)☆53Updated 2 weeks ago
- Open Source Vulnerability schema.☆185Updated last week
- StartLeft is an automation tool for generating Threat Models written in the Open Threat Model (OTM) format from a variety of different so…☆48Updated last week
- ☆80Updated this week
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆174Updated 4 months ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆75Updated this week
- Check SPDX SBOM for NTIA minimum elements☆53Updated this week
- PURL to CPE Relationship mapping project.☆77Updated this week
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆247Updated this week
- Core model including reused documentation☆88Updated last month
- A dataset of software supply chain compromises. Please help us maintain it!☆126Updated 2 years ago
- OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Is…☆49Updated 2 months ago
- Python implementation of Stakeholder-Specific Vulnerability Categorization (SSVC)☆18Updated this week
- ☆17Updated 6 months ago
- Repository for on-going work as part of the AIBOM Tiger Team effort.☆16Updated 2 months ago
- Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data☆57Updated 7 months ago
- Format agnostic SBOM tooling☆78Updated this week