fossas / fossa-cliLinks
Fast, portable and reliable dependency analysis for any codebase. Supports license & vulnerability scanning for large monoliths. Language-agnostic; integrates with 20+ build systems.
☆1,411Updated this week
Alternatives and similar repositories for fossa-cli
Users that are interested in fossa-cli are comparing it to the libraries listed below
Sorting:
- A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby☆843Updated last week
- Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dock…☆995Updated last year
- Python reference implementation of The Update Framework (TUF)☆1,672Updated this week
- A Ruby gem to cache and verify the licenses of dependencies☆1,013Updated last week
- The Buildkite Agent is an open-source toolkit written in Go for securely running build jobs on any device or network☆860Updated this week
- Artifact Metadata API☆1,545Updated 2 weeks ago
- ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party package…☆2,341Updated last week
- Supply-chain Levels for Software Artifacts☆1,703Updated last week
- 🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)☆1,274Updated this week
- SQL interface to git repositories, written in Go. https://docs.sourced.tech/gitbase☆2,079Updated last year
- Notary is a project that allows anyone to have trust over arbitrary collections of data☆3,282Updated last year
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆406Updated last week
- Scalar: A set of tools and extensions for Git to allow very large monorepos to run on Git without a virtualization layer☆1,461Updated 5 months ago
- OpenSSF Scorecard - Security health metrics for Open Source☆5,010Updated this week
- High-performance extensible build system for reproducible multi-language builds.☆2,530Updated last week
- A Ruby Gem to detect under what license a project is distributed.☆849Updated this week
- A GitHub App built with Probot that closes abandoned Issues and Pull Requests after a period of inactivity.☆1,264Updated 2 years ago
- Pull Requests for GitHub repository settings☆992Updated last week
- A suite of tools to automate software compliance checks.☆1,794Updated this week
- Compute various size metrics for a Git repository, flagging those that might cause problems☆3,843Updated 11 months ago
- CUE has moved to https://github.com/cue-lang/cue☆3,075Updated 4 years ago
- Snyk CLI scans and monitors your projects for security vulnerabilities.☆5,187Updated this week
- Contributor License Agreement assistant (CLA assistant)☆1,426Updated last year
- Repolinter, The Open Source Repository Linter☆448Updated 2 weeks ago
- 📅 The web's go-to resource for Calendar Versioning info.☆536Updated last year
- A GitHub App that enforces approval policies on pull requests☆870Updated last week
- A distributed, fault-tolerant pipeline for observability data☆1,743Updated last year
- Open source vulnerability DB and triage service.☆1,937Updated last week
- Curated list of awesome tools for managing open source programs☆473Updated 2 months ago
- The Update Framework specification☆391Updated last year