Semantic SBOM/CBOM/AI-BOM diff, quality scoring, and compliance validation for CycloneDX/SPDX — component, license, and vulnerability change analysis, cryptographic inventory grading, PQC readiness (CNSA 2.0, NIST IR 8547), and regulatory gates for NTIA, FDA, EU CRA, BSI TR-03183, EUCC, SSDF, EO 14028, and the EU AI Act.
☆246Oct 1, 2026Updated last week
Alternatives and similar repositories for sbom-tools
Users that are interested in sbom-tools are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Repository of AI skills specific to CycloneDX☆31Apr 16, 2026Updated 5 months ago
- Data for CyberSOCEval, an LLM benchmark by Meta & CrowdStrike☆24Sep 22, 2025Updated last year
- Vulnerability detection framework by Binarly's REsearch team☆890Aug 25, 2026Updated last month
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆33Sep 1, 2026Updated last month
- SymRustC is a hybrid fuzzer for Rust combining concolic execution using SymCC and fuzzing using LibAFL.☆11Jun 28, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆194Updated this week
- An query language and interactive tooling to work with SBOM data.☆15Oct 7, 2024Updated 2 years ago
- Fuzzers implemented with libafl to evaluate several techniques on fuzzbench☆12Oct 10, 2024Updated last year
- AI Guided Hybrid Application Static Testing☆92Updated this week
- Privateer is a plugin-based framework for security & compliance evaluations.☆28Updated this week
- ☆55Jun 13, 2026Updated 3 months ago
- Performance monitoring agent for eBPF programs☆18Sep 14, 2026Updated 3 weeks ago
- Supply Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆398Sep 24, 2026Updated 2 weeks ago
- GitHub Action to alert on security patches before the CVE drops.☆222Sep 29, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Library for manipulating gdb in batch mode☆21Aug 9, 2026Updated 2 months ago
- GRC Engineer Directory☆20Updated this week
- yet another... tui file manager with a touch of neovim like buffers and modal editing☆17Updated this week
- Sydr benchmark applications☆17Jul 25, 2022Updated 4 years ago
- A curated list of Ransomware resources☆41May 11, 2026Updated 4 months ago
- Built-In zellij user interfaces☆16May 19, 2024Updated 2 years ago
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆384Sep 17, 2026Updated 3 weeks ago
- Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.☆92Updated this week
- Fuzzing Lua runtimes without pain☆16Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆13Apr 24, 2023Updated 3 years ago
- MCP to help Defenders Detection Engineer Harder and Smarter☆496Jun 16, 2026Updated 3 months ago
- Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streaml…☆583Updated this week
- A Minecraft clone built with wgpu and Rust☆22Aug 21, 2024Updated 2 years ago
- Aggregate vulnerability scans from multiple container image scanners to identify discrepancies and get comprehensive exposure analysis.☆86Jul 10, 2026Updated 2 months ago
- Step through and debug AI agent traces without leaving your terminal. Written in Rust.☆16Jun 25, 2026Updated 3 months ago
- Code canaries to quickly triage hallucinated ('slop') vulnerability reports☆100May 20, 2026Updated 4 months ago
- A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.☆182Jul 29, 2026Updated 2 months ago
- 🛡️ Dependency cooldowns are cool!☆104Updated this week
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A tiny small string optimization library.☆24Jul 14, 2026Updated 2 months ago
- ☆15Sep 27, 2026Updated last week
- A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE☆121Updated this week
- A Rust TUI tool to parse boolean expressions and generate truth tables, with K-Map and circuit visualization☆17Aug 21, 2025Updated last year
- PoC shadow SaaS and insecure credential detection system using a browser extension.☆44Aug 5, 2026Updated 2 months ago
- Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-kno…☆25Aug 31, 2026Updated last month
- Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package manager…☆1,085Updated this week