fossas / fossa-cli
Fast, portable and reliable dependency analysis for any codebase. Supports license & vulnerability scanning for large monoliths. Language-agnostic; integrates with 20+ build systems.
☆1,357Updated this week
Alternatives and similar repositories for fossa-cli:
Users that are interested in fossa-cli are comparing it to the libraries listed below
- SQL interface to git repositories, written in Go. https://docs.sourced.tech/gitbase☆2,077Updated last year
- High-performance extensible build system for reproducible multi-language builds.☆2,507Updated this week
- A Ruby gem to cache and verify the licenses of dependencies☆992Updated this week
- Reduce maintainer fatigue by automating GitHub☆812Updated last year
- sso, aka S.S.Octopus, aka octoboi, is a single sign-on solution for securing internal services☆3,111Updated last month
- Scalar: A set of tools and extensions for Git to allow very large monorepos to run on Git without a virtualization layer☆1,432Updated last month
- Fast and flexible Docker image building tool, works in unprivileged containerized environments like Mesos and Kubernetes.☆2,404Updated 3 years ago
- Knox is a secret management service☆1,244Updated last month
- Artifact Metadata API☆1,535Updated this week
- Policy enforcement for your pipelines.☆465Updated this week
- An enterprise friendly way of detecting and preventing secrets in code.☆4,023Updated last month
- A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby☆761Updated this week
- Snyk CLI scans and monitors your projects for security vulnerabilities.☆5,093Updated this week
- CUE has moved to https://github.com/cue-lang/cue☆3,075Updated 3 years ago
- Contributor License Agreement assistant (CLA assistant)☆1,396Updated 10 months ago
- Build powerful pipelines in any programming language.☆5,215Updated last year
- Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dock…☆982Updated last year
- container-diff: Diff your Docker containers☆3,778Updated last year
- ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party package…☆2,263Updated this week
- Software Supply Chain Transparency Log☆951Updated this week
- Starlark Language☆2,612Updated last week
- A suite of tools to automate software compliance checks.☆1,711Updated this week
- Notary is a project that allows anyone to have trust over arbitrary collections of data☆3,270Updated 8 months ago
- GitHub App to set and enforce security policies☆1,296Updated this week
- The Buildkite Agent is an open-source toolkit written in Go for securely running build jobs on any device or network☆834Updated this week
- Find licenses for your project's dependencies.☆1,754Updated 8 months ago
- Copybara: A tool for transforming and moving code between repositories.☆2,314Updated this week
- 🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)☆1,257Updated this week
- GitHub App that enforces the Developer Certificate of Origin (DCO) on Pull Requests☆315Updated 8 months ago
- Fast trigram based code search☆1,728Updated last year