owenrumney / go-sarif
Go library for sarif - Static Analysis Results Interchange Format
☆71Updated last week
Alternatives and similar repositories for go-sarif:
Users that are interested in go-sarif are comparing it to the libraries listed below
- 🚰 Static taint analysis for Go programs.☆62Updated 6 months ago
- Creates CycloneDX Software Bill of Materials (SBOM) from Go modules☆144Updated this week
- Go implementation of the package url spec☆57Updated 2 months ago
- ☆103Updated 6 months ago
- ☆194Updated 2 years ago
- Dependency Parser for Multiple Programming Languages☆146Updated 8 months ago
- ☆56Updated 2 years ago
- Go library to consume and produce CycloneDX Software Bill of Materials (SBOM)☆85Updated this week
- Common Vulnerability Scoring System (CVSS)☆25Updated 11 months ago
- Static code analysis tool to find unsafe usages in Go packages and their dependencies☆42Updated 4 years ago
- Automatic fuzz targets generation for Golang packages☆53Updated last month
- ☆25Updated 9 months ago
- Go module to generate and transform VEX documents☆38Updated last week
- Reliable project licenses detector.☆132Updated 9 months ago
- SARIF Microsoft Visual Studio Code extension☆113Updated 4 months ago
- A lightweight CLI tool that finds system calls being called inside golang applications.☆31Updated 3 years ago
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆135Updated this week
- Go binary license checker. Extracts module usage information from binaries and analyses their licenses.☆70Updated last year
- Auto-gen Go fuzzing wrappers from normal code. Finds buggy call sequences, including data races & deadlocks. Supports rich signature type…☆106Updated 7 months ago
- Go rules for semgrep and go-ruleguard☆466Updated 3 months ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- ☆65Updated this week
- [mirror] the database client and tools for the Go vulnerability database☆399Updated last week
- A Go library for CPE (A Common Platform Enumeration 2.3)☆35Updated last year
- Manage a directory of binaries without a package manager☆25Updated this week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Securing Alice's, Bob's and Carl's software supply chain using in-toto☆90Updated last week
- A golang library for parsing deb package versions☆38Updated 3 months ago
- Reports on the licenses used by a Go package and its dependencies.☆10Updated 7 months ago
- Creates CycloneDX Software Bill-of-Materials (SBOM) from Go projects. So you can use it with DependencyTrack to monitor security issues i…☆21Updated 5 years ago