anthonyharrison / sbom-managerLinks
Manage collection of SBOMs (Software Bill of Materials)
☆14Updated last year
Alternatives and similar repositories for sbom-manager
Users that are interested in sbom-manager are comparing it to the libraries listed below
Sorting:
- A place to systematically store software bill of materials (SBOM) documents.☆47Updated 2 years ago
- SBOM Explorer - Discover and pull public SBOMs☆20Updated 5 months ago
- OpenSSF Project Template☆20Updated last year
- SBOM Search - Context aware search in SBOM repositories☆29Updated last week
- ☆13Updated 9 months ago
- vexctl is a tool to attest VEX impact statements☆45Updated 2 years ago
- Compare vulnerability scanners results (to make them better!)☆23Updated last week
- Decision trees generated via Graphviz to inform pragmatic threat modelling.☆11Updated 4 years ago
- Sharing software supply chain security open source projects☆52Updated 2 years ago
- List of SBOM Generation Tools☆29Updated 8 months ago
- Modular framework for file information extraction and dependency analysis to generate accurate SBOMs☆36Updated last week
- ☆30Updated last week
- Format agnostic SBOM tooling☆121Updated last week
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 9 months ago
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Updated last year
- A specification including, problem statement, use cases, requirements, and architectural constituents for a Transparency Service in suppo…☆14Updated 2 years ago
- Docker Secure Computing Profile Generator☆49Updated 4 years ago
- ☆54Updated this week
- ☆11Updated last week
- Protect your Cloud Native Applications running on Kubernetes from malicious attacks with pre-registered source code, pre-registered runti…☆57Updated 11 months ago
- Audit C/C++ projects (make, cmake, command line, etc.)☆27Updated 4 years ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated 2 years ago
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆33Updated 6 months ago
- ☆102Updated last year
- ☆15Updated this week
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆105Updated this week
- Log monitor for Rekor to verify immutability and monitor entries☆37Updated last week
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆13Updated last week
- A CVRF CSAF Converter, taking care about OASIS specification.☆10Updated 5 months ago