fossas / fossa-cli
Fast, portable and reliable dependency analysis for any codebase. Supports license & vulnerability scanning for large monoliths. Language-agnostic; integrates with 20+ build systems.
☆1,323Updated this week
Alternatives and similar repositories for fossa-cli:
Users that are interested in fossa-cli are comparing it to the libraries listed below
- A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby☆724Updated this week
- SQL interface to git repositories, written in Go. https://docs.sourced.tech/gitbase☆2,070Updated last year
- Reduce maintainer fatigue by automating GitHub☆810Updated 9 months ago
- Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dock…☆972Updated 10 months ago
- The Open Source Discovery Service☆1,123Updated this week
- A fast partial replacement for the codemod tool☆1,710Updated 2 weeks ago
- Repolinter, The Open Source Repository Linter☆432Updated 4 months ago
- LGTM is a simple pull request approval system [ARCHIVE]☆987Updated 7 years ago
- Pull Requests for GitHub repository settings☆953Updated this week
- A License Classifier☆321Updated 3 weeks ago
- Compute various size metrics for a Git repository, flagging those that might cause problems☆3,694Updated 5 months ago
- Fast trigram based code search☆1,718Updated last year
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆376Updated last week
- Correct commonly misspelled English words in source files☆1,363Updated 7 months ago
- ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party package…☆2,187Updated last week
- GitHub App that enforces the Developer Certificate of Origin (DCO) on Pull Requests☆310Updated 6 months ago
- Keep your fish fresh!☆812Updated 2 years ago
- Python reference implementation of The Update Framework (TUF)☆1,640Updated this week
- A GitHub App built with Probot that closes abandoned Issues and Pull Requests after a period of inactivity.☆1,255Updated last year
- CLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys☆1,157Updated last year
- Gaining advanced insights from Git repository history.☆2,657Updated last year
- 📅 The web's go-to resource for Calendar Versioning info.☆513Updated 8 months ago
- 🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)☆1,235Updated this week
- Curated list of awesome tools for managing open source programs☆460Updated last year
- 🤖 Dependabot's core logic for creating update PRs.☆4,829Updated this week
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,516Updated 5 years ago
- Modern Make☆1,721Updated last year
- Dashboards using YAML or JSON files☆1,568Updated last year
- Notary is a project that allows anyone to have trust over arbitrary collections of data☆3,244Updated 5 months ago
- FOSSology is an open source license compliance software system and toolkit. As a toolkit you can run license, copyright and export contr…☆827Updated this week