blackducksoftware / blackduck-docker-inspector
☆21Updated 2 years ago
Alternatives and similar repositories for blackduck-docker-inspector:
Users that are interested in blackduck-docker-inspector are comparing it to the libraries listed below
- A simple Java command-line utility to mirror the entire contents of VulnDB.☆44Updated 2 months ago
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- Scanning and analysis for Black Duck SCA products.☆170Updated this week
- Aqua Enterprise scanner as a plug-in vulnerability scanner in the Harbor registry☆36Updated 4 months ago
- Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).☆134Updated 2 weeks ago
- Jenkins plugin that adds Anchore container image analysis and policy evaluation to Jenkins as a build step☆29Updated 2 months ago
- Enables scanning of docker builds in Jenkins for OS package vulnerabilities.☆35Updated last year
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆86Updated this week
- Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data☆57Updated 10 months ago
- Synopsys Detect integration with Github Actions☆17Updated last year
- Dockerized version of Nexus IQ Server☆26Updated 2 weeks ago
- Integrates OWASP Zed Attack Proxy reports into SonarQube☆70Updated last year
- ahab is a tool to check for vulnerabilities in your apt, apk, or yum powered operating systems, powered by Sonatype OSS Index.☆68Updated 10 months ago
- Evaluation Framework for Dependency Analysis (EFDA)☆43Updated 2 years ago
- The OWASP ZAP Jenkins Plugin extends the functionality of the ZAP security tool into a CI Environment.☆58Updated 4 months ago
- Utility that provides an API and CLI to identify licenses and legal terms☆43Updated 8 months ago
- Produce an Open Source Vulnerability JSON file based on information in an SPDX document☆63Updated 8 months ago
- Software Component Verification Standard (SCVS)☆140Updated 10 months ago
- Grype vulnerability check plugin for Visual Studio Code☆22Updated 2 months ago
- This Repository contains the stable beta preview of the next major secureCodeBox (SCB) release v2.0.0.☆24Updated 4 years ago
- Harbor Scanner Adapter for Anchore Engine and Enterprise☆37Updated this week
- Check SPDX SBOM for NTIA minimum elements☆60Updated 2 weeks ago
- Contains scripts for running anchore engine in CI pipelines☆34Updated 2 years ago
- Incubating project for decoupling responsibilities from Dependency-Track's monolithic API server into separate, scalable services.☆66Updated this week
- Links and resources for the O'Reilly Kubernetes Security book☆98Updated 4 years ago
- CVE Vulnerability scanner of your software bill of materials (SBOM). ASCII text input.☆17Updated 4 years ago
- ☆92Updated 4 months ago
- Identify vulnerable libraries in Maven dependencies☆46Updated 2 years ago
- Static Analysis Library for Containers☆199Updated last year
- A framework for defining ratings for open source projects. In particular, the framework offers a security rating for open source projects…☆61Updated last month