endorlabs / sbom-lab
Evaluate and compare SBOMs of Maven projects
☆12Updated 2 years ago
Alternatives and similar repositories for sbom-lab:
Users that are interested in sbom-lab are comparing it to the libraries listed below
- GitHub action to run Threagile, the agile threat modeling toolkit, on a repo's threagile.yaml file☆13Updated 11 months ago
- CVE database☆22Updated 4 years ago
- ZAP Management Scripts☆23Updated 3 weeks ago
- A place to systematically store software bill of materials (SBOM) documents.☆46Updated last year
- Collection of dynamic security related helpers☆16Updated 2 years ago
- SBOM Grep - search through SBOMs☆25Updated 2 months ago
- CVE Vulnerability scanner of your software bill of materials (SBOM). ASCII text input.☆17Updated 4 years ago
- DefectDojo Community Content☆18Updated 6 months ago
- Sample code snippets for consuming the CloudSploit API☆13Updated last year
- Sharing software supply chain security open source projects☆49Updated 2 years ago
- Highly automated, up-to-date, and well-documented repository template. Checks for common problems, Markdown, YAML, Bash, formats, lints, …☆15Updated last year
- ☆16Updated 8 months ago
- ☆13Updated this week
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆40Updated this week
- INTERCEPT / Policy as Code Auditing & Compliance☆84Updated 3 months ago
- TACOS framework structural details☆20Updated last year
- A project to visualize the software supply chain☆45Updated last year
- Salesforce Policy Deviation Checker☆30Updated 4 years ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- Produce an Open Source Vulnerability JSON file based on information in an SPDX document☆64Updated 10 months ago
- ☆29Updated this week
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- A Java library for programmatically calculating OWASP Risk Rating scores☆18Updated 2 years ago
- Utility that converts SBOM documents from CycloneDX to SPDX☆28Updated last year
- The SCANOSS SBOM Workbench graphical user interface to scan and audit your source code.☆51Updated this week
- ☆28Updated 2 years ago
- An auto-scoring capture-the-flag game focusing on TOCTOU vulnerabilities☆19Updated 4 years ago
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆28Updated 2 months ago
- A community collection of security reviews of open source software components.☆93Updated last year
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 2 months ago