fossas / fossa-cliLinks
Fast, portable and reliable dependency analysis for any codebase. Supports license & vulnerability scanning for large monoliths. Language-agnostic; integrates with 20+ build systems.
☆1,435Updated this week
Alternatives and similar repositories for fossa-cli
Users that are interested in fossa-cli are comparing it to the libraries listed below
Sorting:
- Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dock…☆1,003Updated last year
- GitHub's employee intellectual property agreement, open sourced and reusable☆2,178Updated 4 months ago
- Python reference implementation of The Update Framework (TUF)☆1,679Updated this week
- A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby☆898Updated last week
- A suite of tools to automate software compliance checks.☆1,839Updated this week
- Repolinter, The Open Source Repository Linter☆457Updated last month
- 🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)☆1,291Updated this week
- Artifact Metadata API☆1,549Updated last week
- SQL interface to git repositories, written in Go. https://docs.sourced.tech/gitbase☆2,079Updated 2 years ago
- Pull Requests for GitHub repository settings☆1,001Updated this week
- Notary is a project that allows anyone to have trust over arbitrary collections of data☆3,284Updated last year
- A Ruby gem to cache and verify the licenses of dependencies☆1,014Updated this week
- A GitHub App built with Probot that closes abandoned Issues and Pull Requests after a period of inactivity.☆1,261Updated 2 years ago
- Compute various size metrics for a Git repository, flagging those that might cause problems☆3,893Updated last month
- A program which ensures source code files have copyright license headers by scanning directory patterns recursively☆845Updated this week
- Contributor License Agreement assistant (CLA assistant)☆1,441Updated last year
- Policy enforcement for your pipelines.☆487Updated last week
- 👁 A merge bot for GitHub Pull Requests☆1,526Updated last year
- The Buildkite Agent is an open-source toolkit written in Go for securely running build jobs on any device or network☆893Updated this week
- The Open Source Discovery Service☆1,135Updated this week
- GitHub App to set and enforce security policies☆1,366Updated this week
- Supply-chain Levels for Software Artifacts☆1,742Updated last week
- Knox is a secret management service☆1,252Updated 5 months ago
- Scalar: A set of tools and extensions for Git to allow very large monorepos to run on Git without a virtualization layer☆1,469Updated 8 months ago
- High-performance extensible build system for reproducible multi-language builds.☆2,550Updated last week
- container-diff: Diff your Docker containers☆3,792Updated last year
- An opinionated Dockerfile linter.☆1,022Updated 2 years ago
- LGTM is a simple pull request approval system [ARCHIVE]☆989Updated 7 years ago
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,413Updated last week
- 🤖 All the missing GitHub automation 🙂 🙌☆709Updated last year