owenrumney / go-sarif
Go library for SARIF - Static Analysis Results Interchange Format
☆73Updated last week
Alternatives and similar repositories for go-sarif:
Users that are interested in go-sarif are comparing it to the libraries listed below
- 🚰 Static taint analysis for Go programs.☆63Updated 3 weeks ago
- Creates CycloneDX Software Bill of Materials (SBOM) from Go modules☆151Updated last week
- Go implementation of the package url spec☆58Updated last month
- ☆56Updated 2 years ago
- Dependency Parser for Multiple Programming Languages☆147Updated 9 months ago
- ☆195Updated 2 years ago
- Go library for Sigstore signing and verification☆60Updated last week
- Go library to consume and produce CycloneDX Software Bill of Materials (SBOM)☆86Updated this week
- ☆105Updated 7 months ago
- Collection of Go packages to work with SPDX files☆143Updated last month
- A Server Side Request Forgery (SSRF) protection library. Made with 🖤 by Doyensec LLC.☆100Updated 10 months ago
- Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations☆56Updated last month
- ☆65Updated last week
- Go module to generate and transform VEX documents☆39Updated last week
- ✨🔐 CNCF Fuzzers☆122Updated last month
- [Experimental] jail for Go modules☆83Updated last week
- Common Vulnerability Scoring System (CVSS)☆25Updated last year
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆136Updated this week
- ☆25Updated 10 months ago
- go library for processing container images and simulating a squash filesystem☆90Updated this week
- Reliable project licenses detector.☆134Updated 10 months ago
- Intentionally vulnerable Go web app.☆43Updated 2 months ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- SARIF Microsoft Visual Studio Code extension☆113Updated last week
- Proposed filepath.SecureJoin implementation☆103Updated 3 weeks ago
- Automatic fuzz targets generation for Golang packages☆53Updated 2 months ago
- A tool for interacting with live processes/containers☆22Updated 2 years ago
- Static Analysis Library for Containers☆198Updated last year
- Trivy's misconfiguration scanning engine☆216Updated 2 months ago
- A tool to create, transform and attest VEX metadata☆133Updated this week