opensbom-generator / spdx-sbom-generator
Support CI generation of SBOMs via golang tooling.
☆418Updated this week
Alternatives and similar repositories for spdx-sbom-generator:
Users that are interested in spdx-sbom-generator are comparing it to the libraries listed below
- CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.☆325Updated last month
- OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reductio…☆376Updated this week
- A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles☆497Updated 2 months ago
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆536Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆224Updated 5 months ago
- A utility to generate SPDX-compliant Bill of Materials manifests☆361Updated this week
- A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)☆189Updated last month
- SBOM quality score - Quality metrics for your sboms☆192Updated this week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆423Updated this week
- Utility that provides an API platform for validating, querying and managing BOM data☆98Updated last month
- Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package manager…☆610Updated this week
- GitHub Action for creating software bill of materials using Syft.☆175Updated 3 weeks ago
- A BOM repository server for distributing CycloneDX BOMs☆75Updated 10 months ago
- A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby☆719Updated 3 weeks ago
- in-toto Attestation Framework☆256Updated this week
- Common go library shared across sigstore services and clients☆458Updated this week
- ☆228Updated this week
- A universal SBOM representation in protocol buffers☆273Updated this week
- Software Supply Chain Transparency Log☆917Updated this week
- ☆101Updated 3 months ago
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,314Updated this week
- Check SPDX SBOM for NTIA minimum elements☆58Updated this week
- OpenVEX Specification☆139Updated 6 months ago
- Open Source Vulnerability schema.☆189Updated last week
- Enrich SBOMs with data from third party services☆151Updated last week
- PURL to CPE Relationship mapping project.☆82Updated this week
- CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments☆260Updated this week
- Search an SBOM for licenses and the packages they belong to☆70Updated this week
- Incubating project for decoupling responsibilities from Dependency-Track's monolithic API server into separate, scalable services.☆65Updated this week
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆61Updated 2 weeks ago