intel / cve-bin-tool-actionLinks
Known vulnerability scanning for your GitHub repository using CVE Binary Tool. This Action can scan binaries, component lists and SBOMs for known vulnerabilities and CVEs. It can generate SBOM component lists as well as reports in the Security Tab and in HTML/JSON/PDF format.
☆15Updated 3 months ago
Alternatives and similar repositories for cve-bin-tool-action
Users that are interested in cve-bin-tool-action are comparing it to the libraries listed below
Sorting:
- GitHub Action to autograde projects based on a configurable set of metrics☆30Updated last week
- SARIF Microsoft Visual Studio Code extension☆132Updated this week
- A CLI tool for creating secure by design/default source repos.☆28Updated last year
- CLOWarden is a tool that manages access to resources across multiple services☆61Updated last week
- Examples of SPDX files for software combinations☆142Updated 2 months ago
- OASIS SARIF TC: Repository for development of the draft standard, where requests for modification should be made via Github Issues☆192Updated this week
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated last year
- TUF repository for Sigstore trust root☆117Updated this week
- ☆20Updated last week
- ahab is a tool to check for vulnerabilities in your apt, apk, or yum powered operating systems, powered by Sonatype OSS Index.☆68Updated 2 weeks ago
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆33Updated 9 months ago
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆186Updated this week
- A light-weight app to audit and inventory large codebases for open source license compliance.☆72Updated this week
- Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.☆112Updated this week
- ☆102Updated last year
- Invite users to a GitHub team in bulk☆12Updated 4 years ago
- Compare vulnerability scanners results (to make them better!)☆27Updated last week
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Updated last year
- ☆122Updated 9 months ago
- Action to detect if a secret is initially detected in a pull request☆19Updated this week
- The model for the information captured in SPDX version 3 standard.☆97Updated 2 weeks ago
- The service side of clearlydefined.io☆50Updated this week
- Automating Compliance Tooling Project☆22Updated 4 years ago
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆33Updated 2 years ago
- SCANOSS Open Source Inventory Engine☆41Updated this week
- Github Action implementation of SLSA Provenance Generation☆50Updated this week
- Generate SBOMs with gh CLI☆198Updated 8 months ago
- Lockheed Martin developed utility to combine multiple CycloneDX SBOMs☆13Updated 3 years ago
- GitHub Secret Scanning Auto Remediator (GSSAR)☆46Updated last month
- Manage collection of SBOMs (Software Bill of Materials)☆14Updated last year