A tool to generate a SBOM (Software Bill of Materials) for an installed Python module
☆37Mar 13, 2026Updated last week
Alternatives and similar repositories for sbom4python
Users that are interested in sbom4python are comparing it to the libraries listed below
Sorting:
- The Hyperdiv documentation app, implemented in Hyperdiv☆12Oct 14, 2025Updated 5 months ago
- The Keep It Simple Software Bill of Material☆11Jan 31, 2022Updated 4 years ago
- Binary builds for dep-scan - The Dependency Scanner☆10Apr 1, 2024Updated last year
- A specification including, problem statement, use cases, requirements, and architectural constituents for a Transparency Service in suppo…☆14Feb 17, 2023Updated 3 years ago
- Create a dependency graph of the components within a SBOM☆18Aug 17, 2025Updated 7 months ago
- Linear algebra utilities for Python☆13Oct 28, 2025Updated 4 months ago
- Transform SBOM contents into a formatted document including markdown and PDF formats☆38Jan 26, 2026Updated last month
- Report on quality of SBOM contents☆25Dec 18, 2024Updated last year
- Fetches security vulnerabilities and creates pip-constraints based on them.☆12Jan 27, 2025Updated last year
- Repository for on-going work as part of the SBOM for AI Tiger Team effort.☆42Jul 28, 2025Updated 7 months ago
- Linux agent used to submit realtime SBOMs and dependency usage information to EdgeBit☆15Jan 24, 2025Updated last year
- a mostly correct pip requirements parsing library☆20Sep 2, 2024Updated last year
- Kubernetes TPM Device Plugin☆13Jun 15, 2023Updated 2 years ago
- apt2sbom python package generates SPDX or CycloneDX files from Ubuntu APT and Python packaging information☆25Feb 4, 2022Updated 4 years ago
- Trivy plugin for OCI referrers☆23May 13, 2024Updated last year
- ☆11Nov 11, 2022Updated 3 years ago
- Script to help maintain a wheelhouse folder on a cloud storage.☆33Aug 4, 2020Updated 5 years ago
- Analysis of your architecture strength based on DSM data.☆12Jan 11, 2024Updated 2 years ago
- Inspect Python code and PyPI package manifests. Resolve Python dependencies.☆24Mar 11, 2026Updated last week
- A standard API specification for exchanging supply chain artifacts and intelligence☆103Mar 13, 2026Updated last week
- Flake8 Plugin that Forbids Implicit str/bytes Literal Concatenations☆20Mar 2, 2026Updated 2 weeks ago
- SuperGenPass Python module and GTK interface, compatible with Android app of Steve Pomeroy☆10Mar 11, 2013Updated 13 years ago
- CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments☆362Updated this week
- A software suite for enhancing software supply chain transparency☆31Feb 16, 2026Updated last month
- A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles☆572May 20, 2025Updated 10 months ago
- 🚀 A simple platform and shell agnostic installer and version manager for Go.☆11Jan 4, 2025Updated last year
- An easy-to-use, informative CLI for accessing Pokémon summaries.☆10Nov 13, 2022Updated 3 years ago
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆75Mar 13, 2026Updated last week
- Read rmp archive files☆29Aug 15, 2025Updated 7 months ago
- Go stemmers generated by the Snowball project☆24Sep 6, 2020Updated 5 years ago
- Log monitor for Rekor to verify immutability and monitor entries☆48Updated this week
- Statically analyze sources and extract information about called or exported library functions in Python applications☆21Apr 25, 2024Updated last year
- RKD - RiotKit DO. Task executor - balance between Makefile and Gradle. Written in Python. Powerful tool for every DevOps. Automates produ…☆10May 6, 2022Updated 3 years ago
- Python bindings for TrustyAI's explainability library☆19Dec 3, 2025Updated 3 months ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆19Mar 5, 2026Updated 2 weeks ago
- Vendy is a tool for vendoring third-party packages into your project.☆18Nov 28, 2023Updated 2 years ago
- A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain☆98Feb 11, 2025Updated last year
- Linux integrity monitoring for CentOS/RHEL☆13May 13, 2020Updated 5 years ago
- A command line tool that compares two versions of a NuGet package and provides public API differences☆14Feb 24, 2025Updated last year