carbonetes / diggity
Generates SBOMs for container images, filesystems, archives, and more to Discover packages and libraries Highly scalable data pipelines for loading data
☆102Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for diggity
- A Github Action that utilizes Diggity to generate software bill-of-materials (SBOM).☆14Updated last year
- Jacked provides organizations with a more comprehensive look at their application to take calculated actions and create a better security…☆100Updated 2 months ago
- ☆18Updated 3 months ago
- BrainIAC uses static code analysis to analyze IAC code to detect security issues before deployment. This tool can scan for issues like se…☆68Updated 2 months ago
- ☆34Updated last year
- OWASP Foundation Web Respository☆16Updated 3 weeks ago
- Agile authoring tutorial and repo set-up tooling☆18Updated 2 months ago
- A community wiki for all things AI/ML bill of materials (MLBOM, AIBOM) and transparency into AI/ML models.☆33Updated 2 weeks ago
- Utility that provides an API platform for validating, querying and managing BOM data☆95Updated this week
- Repository for the SBOM Harbor.☆17Updated last year
- Stakeholder-Specific Vulnerability Categorization☆130Updated this week
- NIST SP 800-171 OSCAL Content☆13Updated 2 years ago
- Lockheed Martin developed utility to compare two CycloneDX SBOMs☆18Updated 3 years ago
- List of SBOM Generation Tools☆20Updated last week
- A tool that takes two or more micro SBOMs and composes them into one distributable SBOM☆23Updated last year
- Measure release insights and recommendations for open-source dependencies. Note: this project is archived.☆11Updated last year
- Go module to generate and transform VEX documents☆34Updated 3 weeks ago
- A light-weight app to audit and inventory large codebases for open source license compliance.☆60Updated this week
- Java libraries for working with available vulnerability data sources (GitHub Security Advisories, NVD, EPSS, CISA Known Exploited Vulnera…☆124Updated this week
- Exploit Prediction Scoring System (EPSS)☆23Updated 2 years ago
- Autoconfigured ELK Stack That Contains All EPSS and NVD CVE Data☆47Updated 4 months ago
- A set of Jupyter Lab Notebooks and Other Implementations of Community Reports in Standard Form☆15Updated 7 months ago
- Gatecheck CI/CD Validation Tool☆14Updated 5 months ago
- Audit Dependency-Track findings and policy violations via policy as code☆32Updated this week
- Posture Attribute Collection and Evaluation☆23Updated last year
- Support CI generation of SBOMs via golang tooling.☆408Updated 10 months ago
- Skyflow SDK for the Go programming language.☆11Updated this week
- 🏛️ 🗣️ ☁️ CNCF User Group focused on advancing cloud computing in the public sector☆21Updated last month
- ☆18Updated 5 months ago
- Debricked's command line interface. It brings open source security, compliance and health to your project via the command prompt.☆20Updated this week