A tool to create, transform and attest VEX metadata
☆194Jun 3, 2026Updated last week
Alternatives and similar repositories for vexctl
Users that are interested in vexctl are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Go module to generate and transform VEX documents☆65Jun 4, 2026Updated last week
- OpenVEX Specification☆182Jan 16, 2026Updated 4 months ago
- An SBOM query language and associated utilities☆56Jan 22, 2024Updated 2 years ago
- vexctl is a tool to attest VEX impact statements☆45Mar 27, 2023Updated 3 years ago
- Enrich SBOMs with data from third party services☆227May 18, 2026Updated 3 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆150May 22, 2026Updated 2 weeks ago
- A universal SBOM representation in protocol buffers☆326Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆243Aug 13, 2024Updated last year
- ☆83Dec 10, 2025Updated 6 months ago
- Format agnostic SBOM tooling☆137Nov 20, 2025Updated 6 months ago
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆14May 28, 2026Updated last week
- Interfaces and implementations for building Kubernetes releases.☆20Jun 4, 2026Updated last week
- A utility to generate SPDX-compliant Bill of Materials manifests☆456Jun 3, 2026Updated last week
- SPDX Merge tool☆51May 18, 2026Updated 3 weeks ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- ☆102Sep 27, 2024Updated last year
- SBOM Search - Context aware search in SBOM repositories☆32Nov 24, 2025Updated 6 months ago
- Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.☆89Jun 3, 2026Updated last week
- sbomasm: The Complete SBOM Management Toolkit☆118Jun 3, 2026Updated last week
- in-toto Attestation Framework☆338May 18, 2026Updated 3 weeks ago
- Dynamic GitHub Actions from Wolfi packages☆45May 5, 2026Updated last month
- Posture Attribute Collection and Evaluation☆23Jun 20, 2023Updated 2 years ago
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆34Apr 22, 2025Updated last year
- Support CI generation of SBOMs via golang tooling.☆427Jan 13, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆534Jun 1, 2026Updated last week
- A CLI used to work with the Wolfi OSS project☆72Jun 4, 2026Updated last week
- Report on quality of SBOM contents☆27Dec 18, 2024Updated last year
- Build OCI images from APK packages directly without Dockerfile☆1,633Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆112Jun 3, 2026Updated last week
- Scans SBOMs for vulnerabilities with Grype☆87Updated this week
- Reports on the licenses used by a Go package and its dependencies.☆11Jul 24, 2024Updated last year
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,498Updated this week
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆295May 19, 2026Updated 3 weeks ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations☆60Jun 3, 2026Updated last week
- Go implementation of witness☆49Updated this week
- Automating Compliance Tooling Project☆24Jan 28, 2022Updated 4 years ago
- Context aware slog☆31Updated this week
- ☆20Updated this week
- Keyless Git signing using Sigstore☆1,092Updated this week
- ☆16May 14, 2025Updated last year