blackducksoftware / blackduck-docker-inspectorLinks
☆21Updated 3 years ago
Alternatives and similar repositories for blackduck-docker-inspector
Users that are interested in blackduck-docker-inspector are comparing it to the libraries listed below
Sorting:
- Scanning and analysis for Black Duck SCA products.☆187Updated this week
- Integrates OWASP Zed Attack Proxy reports into SonarQube☆72Updated 3 months ago
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- Black Duck Docker Orchestration Files/Documentation☆130Updated last week
- Static Analysis Library for Containers☆197Updated 2 years ago
- This Repository contains the stable beta preview of the next major secureCodeBox (SCB) release v2.0.0.☆24Updated 5 years ago
- Links and resources for the O'Reilly Kubernetes Security book☆100Updated 4 years ago
- Checks whether Docker is deployed according to security best practices as defined in the CIS Docker Benchmark☆222Updated 9 months ago
- Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).☆137Updated this week
- Harbor Scanner Adapter for Anchore Engine and Enterprise☆39Updated last week
- Container Security Verification Standard☆58Updated 6 years ago
- Contains scripts for running anchore engine in CI pipelines☆34Updated 3 years ago
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆207Updated 3 weeks ago
- Utility that provides an API and CLI to identify licenses and legal terms☆53Updated 4 months ago
- Software Component Verification Standard (SCVS)☆150Updated 7 months ago
- Simple command-line client to the Anchore Engine service☆113Updated last year
- ahab is a tool to check for vulnerabilities in your apt, apk, or yum powered operating systems, powered by Sonatype OSS Index.☆68Updated last year
- Securing Alice's, Bob's and Carl's software supply chain using in-toto☆99Updated last month
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆99Updated last week
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆215Updated 5 months ago
- Utility that provides an API platform for validating, querying and managing BOM data☆122Updated last month
- Aqua Enterprise scanner as a plug-in vulnerability scanner in the Harbor registry☆36Updated last year
- Plugin for Docker CLI to support SBOM creation using Syft☆160Updated last week
- Integrates Xanitizer results into SonarQube☆21Updated 4 years ago
- ☆51Updated 5 years ago
- A Java library for calculating CVSSv2, CVSSv3, and CVSSv4 scores and vectors☆49Updated last week
- A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.☆61Updated 5 months ago
- Kubernetes Common Configuration Scoring System☆122Updated 3 years ago
- Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data☆65Updated last year
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆203Updated last month