philips-software / license-scanner
Service to scan licenses from source code
☆12Updated last year
Related projects ⓘ
Alternatives and complementary repositories for license-scanner
- Low-effort reachability analysis for third-party code vulnerabilities.☆20Updated last year
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 2 weeks ago
- CVE database☆22Updated 4 years ago
- Report missing advisories and corrections on OSS Index☆17Updated last year
- A library for parsing security advisories☆13Updated 2 months ago
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- OSS License Open Data☆12Updated 5 years ago
- A framework for defining ratings for open source projects. In particular, the framework offers a security rating for open source projects…☆60Updated last week
- The Keep It Simple Software Bill of Material☆11Updated 2 years ago
- apt2sbom python package generates SPDX or CycloneDX files from Ubuntu APT and Python packaging information☆22Updated 2 years ago
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆57Updated 3 weeks ago
- A CVRF CSAF Converter, taking care about OASIS specification.☆10Updated last year
- Automating Compliance Tooling Project☆20Updated 2 years ago
- container-inspector is a suite of analysis utilities and command line tools for Docker container images, their layers and how these relat…☆34Updated 3 months ago
- Automate open source license compliance and ensure software supply chain integrity☆25Updated this week
- GitHub Action to get a license overview in SPDX format☆14Updated 2 years ago
- SBOM Grep - search through SBOMs☆21Updated 2 months ago
- License Identifier☆14Updated 3 years ago
- Publications done by Double Open.☆16Updated 4 years ago
- SPDX 2.0 document creation and storage☆15Updated last year
- ☆13Updated last month
- ☆19Updated last week
- A community collection of security reviews of open source software components.☆92Updated 8 months ago
- Given a buildinfo file from a Debian package, generate instructions for attempting to reproduce the binary packages built from the associ…☆16Updated 2 years ago
- Generate VEX (Vulnerability Exploitability Exchange) CycloneDX documents☆19Updated last year
- Secvisogram is a web tool for creating and editing security advisories in the CSAF 2.0 format☆19Updated 3 months ago
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Updated 8 months ago
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆12Updated last month
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year