blackducksoftware / hub
Black Duck Docker Orchestration Files/Documentation
☆122Updated 2 weeks ago
Alternatives and similar repositories for hub:
Users that are interested in hub are comparing it to the libraries listed below
- Scanning and analysis for Black Duck SCA products.☆170Updated this week
- HUB REST API Python bindings☆92Updated last month
- Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).☆134Updated 3 weeks ago
- CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.☆343Updated 4 months ago
- A simple Java command-line utility to mirror the CVE JSON data from NIST.☆208Updated 2 years ago
- Simple command-line client to the Anchore Engine service☆114Updated 8 months ago
- Frontend UI for Dependency-Track☆117Updated this week
- SPDX Tools☆134Updated last year
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆389Updated this week
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆92Updated this week
- A utility for validating and parsing Common Platform Enumeration (CPE) v2.2 and v2.3 as originally defined by MITRE and maintained by NIS…☆49Updated last week
- OpenSSF Security Tooling Working Group☆309Updated 10 months ago
- A set of scripts inspired by CIS Kubernetes Benchmark that checks best-practices of Kubernetes installations☆265Updated last year
- Main repository for the official Dependency-Track Jenkins plugin☆47Updated last week
- Check SPDX SBOM for NTIA minimum elements☆60Updated 2 weeks ago
- Integrates OWASP Zed Attack Proxy reports into SonarQube☆70Updated last year
- Support CI generation of SBOMs via golang tooling.☆422Updated 2 months ago
- Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure D…☆148Updated 4 years ago
- CIS Kubernetes Benchmark - InSpec Profile☆300Updated 7 months ago
- ☆21Updated 2 years ago
- Static Analysis Library for Containers☆198Updated last year
- Enables scanning of docker builds in Jenkins for OS package vulnerabilities.☆35Updated last year
- Software Component Verification Standard (SCVS)☆141Updated 11 months ago
- CIS Docker Benchmark - InSpec Profile☆501Updated last year
- Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data☆57Updated 11 months ago
- Home page of project "KB"☆120Updated 2 weeks ago
- A cli that can be used to query various online vulnerability sources such as the NVD or GHSA. The CLI and docker images can be used to mi…☆141Updated this week
- NVD, Ubuntu, Alpine☆425Updated this week
- This project is deprecated. Work is now done on https://github.com/anchore/syft and https://github.com/anchore/grype for local-host Softw…☆361Updated 4 years ago
- Checks whether Docker is deployed according to security best practices as defined in the CIS Docker Benchmark☆215Updated last month