blackducksoftware / blackduck-docker-inspector
☆21Updated 2 years ago
Alternatives and similar repositories for blackduck-docker-inspector:
Users that are interested in blackduck-docker-inspector are comparing it to the libraries listed below
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- A simple Java command-line utility to mirror the entire contents of VulnDB.☆44Updated 3 months ago
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆92Updated this week
- Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data☆57Updated 11 months ago
- A Java library for calculating CVSSv2 and CVSSv3 scores and vectors☆44Updated 3 months ago
- Utility that provides an API and CLI to identify licenses and legal terms☆43Updated 9 months ago
- Scanning and analysis for Black Duck SCA products.☆170Updated this week
- This Repository contains the stable beta preview of the next major secureCodeBox (SCB) release v2.0.0.☆24Updated 4 years ago
- Check SPDX SBOM for NTIA minimum elements☆60Updated 2 weeks ago
- Aqua Enterprise scanner as a plug-in vulnerability scanner in the Harbor registry☆36Updated 5 months ago
- Software Component Verification Standard (SCVS)☆141Updated 11 months ago
- Links and resources for the O'Reilly Kubernetes Security book☆98Updated 4 years ago
- OWASP Dependency Track API client for intergration into CI/CD pipeline☆53Updated 7 months ago
- Harbor Scanner Adapter for Anchore Engine and Enterprise☆37Updated this week
- Dockerized version of Nexus IQ Server☆26Updated this week
- Trivy kubernetes library☆33Updated last week
- OpsSight Connector documentation☆16Updated 3 years ago
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- Integrates OWASP Zed Attack Proxy reports into SonarQube☆70Updated last year
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated last month
- CVE database☆22Updated 4 years ago
- Grype vulnerability check plugin for Visual Studio Code☆22Updated 3 months ago
- This plugin adds an ability to perform automatic code scan by Checkmarx server and shows results summary and trend in Jenkins interface.☆42Updated last week
- Contains scripts for running anchore engine in CI pipelines☆34Updated 2 years ago
- Enables scanning of docker builds in Jenkins for OS package vulnerabilities.☆35Updated last year
- Jenkins plugin that adds Anchore container image analysis and policy evaluation to Jenkins as a build step☆29Updated 3 months ago
- Static Analysis Library for Containers☆198Updated last year
- Utility that provides an API platform for validating, querying and managing BOM data☆104Updated 4 months ago
- Incubating project for decoupling responsibilities from Dependency-Track's monolithic API server into separate, scalable services.☆70Updated this week
- Evaluation Framework for Dependency Analysis (EFDA)☆43Updated 2 years ago