fossas / fossa-cliLinks
Fast, portable and reliable dependency analysis for any codebase. Supports license & vulnerability scanning for large monoliths. Language-agnostic; integrates with 20+ build systems.
☆1,454Updated 2 weeks ago
Alternatives and similar repositories for fossa-cli
Users that are interested in fossa-cli are comparing it to the libraries listed below
Sorting:
- Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dock…☆1,010Updated last year
- Python reference implementation of The Update Framework (TUF)☆1,693Updated last week
- Artifact Metadata API☆1,562Updated last month
- A suite of tools to automate software compliance checks.☆1,889Updated this week
- ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party package…☆2,446Updated last week
- A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby☆935Updated last week
- Gives criticality score for an open source project☆1,415Updated last month
- 🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)☆1,309Updated this week
- The Buildkite Agent is an open-source toolkit written in Go for securely running build jobs on any device or network☆909Updated last week
- Software Supply Chain Transparency Log☆1,056Updated this week
- GitHub App that enforces the Developer Certificate of Origin (DCO) on Pull Requests☆331Updated last month
- SQL interface to git repositories, written in Go. https://docs.sourced.tech/gitbase☆2,083Updated 2 years ago
- Notary is a project that allows anyone to have trust over arbitrary collections of data☆3,284Updated last year
- GitHub App to set and enforce security policies☆1,382Updated 3 weeks ago
- A program which ensures source code files have copyright license headers by scanning directory patterns recursively☆855Updated 2 months ago
- Repolinter, The Open Source Repository Linter☆462Updated last week
- High-performance extensible build system for reproducible multi-language builds.☆2,575Updated 2 weeks ago
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆466Updated 2 weeks ago
- Curated list of awesome tools for managing open source programs☆489Updated last month
- GitHub's employee intellectual property agreement, open sourced and reusable☆2,195Updated 7 months ago
- A GitHub App built with Probot that closes abandoned Issues and Pull Requests after a period of inactivity.☆1,266Updated 2 years ago
- Supply-chain Levels for Software Artifacts☆1,785Updated last week
- Pull Requests for GitHub repository settings☆1,012Updated this week
- in-toto is a framework to protect supply chain integrity.☆966Updated this week
- A GitHub App that enforces approval policies on pull requests☆921Updated last week
- InSpec: Auditing and Testing Framework☆3,023Updated last week
- sso, aka S.S.Octopus, aka octoboi, is a single sign-on solution for securing internal services☆3,117Updated last month
- The Open Source Discovery Service☆1,140Updated 2 months ago
- A service that analyzes docker images and scans for vulnerabilities☆1,594Updated 2 years ago
- CUE has moved to https://github.com/cue-lang/cue☆3,067Updated 4 years ago