SPDX Merge tool
☆51May 18, 2026Updated 3 months ago
Alternatives and similar repositories for SPDXMerge
Users that are interested in SPDXMerge are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- GitHub action to produce a SBOM report from a given Black Duck project☆12Feb 5, 2026Updated 6 months ago
- The model for the information captured in SPDX version 3 standard.☆104Aug 22, 2026Updated last week
- SBOM Move - Automate build and transfer of SBOMs across systems☆27Updated this week
- License Identifier☆15Mar 25, 2021Updated 5 years ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Apr 17, 2023Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Security advisory data for Wolfi☆19Jan 7, 2026Updated 7 months ago
- ☆20Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- Continuous Compliance makes it possible to enforce company policy on repositories. Continuous Compliance will automatically check your re…☆22Nov 24, 2025Updated 9 months ago
- A universal SBOM representation in protocol buffers☆330Updated this week
- Automating Compliance Tooling Project☆24Jan 28, 2022Updated 4 years ago
- Documents and tools powering the Wolfi OS community☆24Apr 22, 2026Updated 4 months ago
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆19Updated this week
- Build a CVE library with aggregated CISA, EPSS and CVSS data☆29Sep 27, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A taxonomy of all official CycloneDX property namespaces and names☆25Updated this week
- Format agnostic SBOM tooling☆156Nov 20, 2025Updated 9 months ago
- A tool to create, transform and attest VEX metadata☆210Updated this week
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.☆35Jan 4, 2026Updated 7 months ago
- apt2sbom python package generates SPDX or CycloneDX files from Ubuntu APT and Python packaging information☆25Feb 4, 2022Updated 4 years ago
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl…☆11Updated this week
- An SBOM query language and associated utilities☆55Jan 22, 2024Updated 2 years ago
- Library to ingest and generate VEX documents☆20Mar 9, 2026Updated 5 months ago
- Red team tool that emulates the SolarWinds CI compromise attack vector.☆24Mar 15, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- OSS License Open Data☆12Jun 28, 2019Updated 7 years ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Oct 24, 2022Updated 3 years ago
- OSS License Simple Viewer is a simple Excel-based tool as OSS license reference for engineers.☆14Nov 20, 2020Updated 5 years ago
- Darkfiles finds orphaned files in container images and makes them to bad deeds