philips-software / license-scanner
Service to scan licenses from source code
☆12Updated last year
Alternatives and similar repositories for license-scanner:
Users that are interested in license-scanner are comparing it to the libraries listed below
- Low-effort reachability analysis for third-party code vulnerabilities.☆20Updated last year
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- OSS License Open Data☆12Updated 5 years ago
- apt2sbom python package generates SPDX or CycloneDX files from Ubuntu APT and Python packaging information☆22Updated 3 years ago
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆62Updated last week
- A library for parsing security advisories☆13Updated 5 months ago
- ☆13Updated 4 months ago
- SBOM Grep - search through SBOMs☆21Updated last week
- A CVRF CSAF Converter, taking care about OASIS specification.☆10Updated last month
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆11Updated this week
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- The SCANOSS SBOM Workbench graphical user interface to scan and audit your source code.☆48Updated this week
- Utility that converts SBOM documents from CycloneDX to SPDX☆29Updated last year
- A Yocto meta-layer for generating CycloneDX SBOMs and automatically uploading them to Dependency Track.☆19Updated 8 months ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 3 weeks ago
- A light-weight app to audit and inventory large codebases for open source license compliance.☆61Updated this week
- The Keep It Simple Software Bill of Material☆11Updated 3 years ago
- Generate VEX (Vulnerability Exploitability Exchange) CycloneDX documents☆19Updated last month
- Automating Compliance Tooling Project☆20Updated 3 years ago
- Parse and compare all the package versions and all the ranges. From debian, npm, pypi, ruby and more. Process all the version range specs…☆33Updated 4 months ago
- Find & pull public SBOMs☆16Updated 5 months ago
- A taxonomy of all official CycloneDX property namespaces and names☆15Updated this week
- Automate open source license compliance and ensure software supply chain integrity☆29Updated this week
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆83Updated this week
- Publications done by Double Open.☆16Updated 4 years ago
- Check SPDX SBOM for NTIA minimum elements☆60Updated 2 weeks ago
- Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulner…☆40Updated this week
- A standard API specification for exchanging supply chain artifacts and intelligence☆72Updated last week
- Audit C/C++ projects (make, cmake, command line, etc.)☆26Updated 3 years ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆78Updated last week