blackducksoftware / hubLinks
Black Duck Docker Orchestration Files/Documentation
☆125Updated last week
Alternatives and similar repositories for hub
Users that are interested in hub are comparing it to the libraries listed below
Sorting:
- Scanning and analysis for Black Duck SCA products.☆180Updated this week
- HUB REST API Python bindings☆95Updated last month
- A simple Java command-line utility to mirror the CVE JSON data from NIST.☆210Updated 2 years ago
- Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).☆138Updated last month
- Integrates OWASP Zed Attack Proxy reports into SonarQube☆72Updated last month
- Simple command-line client to the Anchore Engine service☆114Updated last year
- NVD, Ubuntu, Alpine☆440Updated last week
- ☆21Updated 3 years ago
- A set of scripts inspired by CIS Kubernetes Benchmark that checks best-practices of Kubernetes installations☆266Updated 2 years ago
- Use Trivy as a plug-in vulnerability scanner in the Harbor registry☆225Updated 11 months ago
- Main repository for the official Dependency-Track Jenkins plugin☆51Updated last week
- ☆275Updated last month
- Analyses your Java applications for open-source dependencies with known vulnerabilities, using both static analysis and testing to determ…☆543Updated last year
- Frontend UI for Dependency-Track☆128Updated last week
- A utility for validating and parsing Common Platform Enumeration (CPE) v2.2 and v2.3 as originally defined by MITRE and maintained by NIS…☆53Updated 2 weeks ago
- Checkmarx Scan and Result Orchestration☆101Updated this week
- Run CoreOs Clair standalone☆252Updated 8 months ago
- Evaluation Framework for Dependency Analysis (EFDA)☆43Updated 3 years ago
- CIS Kubernetes Benchmark - InSpec Profile☆307Updated last year
- Support CI generation of SBOMs via golang tooling.☆425Updated 8 months ago
- Enables scanning of docker builds in Jenkins for OS package vulnerabilities.☆35Updated 2 years ago
- Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure D…☆149Updated 5 years ago
- Plugin for Docker CLI to support SBOM creation using Syft☆156Updated 2 weeks ago
- CIS Docker Benchmark - InSpec Profile☆515Updated 2 years ago
- Contains scripts for running anchore engine in CI pipelines☆34Updated 3 years ago
- This project is deprecated. Work is now done on https://github.com/anchore/syft and https://github.com/anchore/grype for local-host Softw…☆362Updated 4 years ago
- SpotBugs plugin for SonarQube☆370Updated 2 weeks ago
- A cli that can be used to query various online vulnerability sources such as the NVD or GHSA. The CLI and docker images can be used to mi…☆147Updated last week
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆212Updated 3 months ago
- Integrates Dependency-Check reports into SonarQube☆663Updated last week