philips-software / spdx-builder
Generates SPDX bill-of-material files from a package input and license scan
☆12Updated 5 months ago
Related projects: ⓘ
- GitHub Action to get a license overview in SPDX format☆14Updated 2 years ago
- Submit SBOMs to GitHub's dependency submission API☆11Updated last year
- Run ORT in your GitHub action workflow to do licensing, security and best practices checks and generate reports/SBOMs☆23Updated 3 months ago
- A java api and command line tool for scanning, reporting and fixing a git repository's InnerSource Readiness based on a supplied specific…☆20Updated last year
- A light-weight app to audit and inventory large codebases for open source license compliance.☆60Updated this week
- SPDX Merge tool☆39Updated last week
- Automating Compliance Tooling Project☆20Updated 2 years ago
- A web based tool for working with CycloneDX BOMs☆29Updated last month
- A BOM repository server for distributing CycloneDX BOMs☆73Updated 6 months ago
- Github Action implementation of SLSA Provenance Generation☆47Updated 2 weeks ago
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆32Updated last year
- Check SPDX SBOM for NTIA minimum elements☆52Updated last week
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆54Updated this week
- A tool that takes two or more micro SBOMs and composes them into one distributable SBOM☆23Updated last year
- List of SBOM Generation Tools☆18Updated 2 months ago
- SBOM quality score - Quality metrics for your sboms☆161Updated this week
- Curations and configuration files for the OSS Review Toolkit.☆15Updated last week
- OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Is…☆49Updated 2 weeks ago
- ☆56Updated 2 months ago
- The model for the information captured in SPDX version 3 standard.☆68Updated this week
- A CLI tool for creating secure by design/default source repos.☆24Updated last month
- Produce an Open Source Vulnerability JSON file based on information in an SPDX document☆60Updated 3 months ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆31Updated 2 months ago
- Utility that converts SBOM documents from CycloneDX to SPDX☆29Updated 8 months ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated this week
- Use ORT in your GitLab pipelines☆13Updated 2 months ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated last year
- Format agnostic SBOM tooling☆63Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆219Updated last month
- A tool to generate a SBOM (Software Bill of Materials) for an installed Python module☆25Updated 3 weeks ago