carbonetes / diggity
Generates SBOMs for container images, filesystems, archives, and more to Discover packages and libraries Highly scalable data pipelines for loading data
☆105Updated 2 weeks ago
Alternatives and similar repositories for diggity:
Users that are interested in diggity are comparing it to the libraries listed below
- Jacked provides organizations with a more comprehensive look at their application to take calculated actions and create a better security…☆102Updated last month
- A Github Action that utilizes Diggity to generate software bill-of-materials (SBOM).☆14Updated 2 years ago
- ☆18Updated 8 months ago
- BrainIAC uses static code analysis to analyze IAC code to detect security issues before deployment. This tool can scan for issues like se…☆70Updated 6 months ago
- FedRAMP Automation☆16Updated last year
- ☆35Updated 2 years ago
- Generate VEX (Vulnerability Exploitability Exchange) CycloneDX documents☆20Updated 2 months ago
- This repository contains a SonarQube Plugin that detects cryptographic assets in source code and generates CBOM.☆32Updated last week
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 2 months ago
- Repository for the generation of OSCAL data types☆23Updated last week
- Terraform for notification.canada.ca☆14Updated this week
- ☆16Updated 3 weeks ago
- ☆16Updated 7 months ago
- Awesome AWS service control policies (SCPs)☆25Updated 2 months ago
- The Compliance Validator☆170Updated last week
- Incubating project for decoupling responsibilities from Dependency-Track's monolithic API server into separate, scalable services.☆70Updated this week
- Search an SBOM for licenses and the packages they belong to☆83Updated this week
- A case study for ACSAC 2022 utilizing OSCAL with a custom GitHub action to automate assessments.☆24Updated 2 years ago
- A CLI tool for creating secure by design/default source repos.☆25Updated 8 months ago
- ☆11Updated 4 months ago
- A BOM repository server for distributing CycloneDX BOMs☆77Updated last year
- Takes a software bill of materials and outputs provenance, and activity data from trustypkg.dev☆11Updated 6 months ago
- Visualizer for GUAC☆28Updated 3 weeks ago
- The community area and documents about Code of Conduct.☆18Updated 4 years ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆18Updated 2 weeks ago
- ☆16Updated last year
- A standard API specification for exchanging supply chain artifacts and intelligence☆75Updated 3 weeks ago
- Cryptography Bill of Materials☆66Updated last month
- Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data☆57Updated last year
- Exports vulnerability scan data from the Checkmarx SAST platform for use in analytical tools.☆19Updated 5 months ago