Semantic SBOM/CBOM/AI-BOM diff, quality scoring, and compliance validation for CycloneDX/SPDX — component, license, and vulnerability change analysis, cryptographic inventory grading, PQC readiness (CNSA 2.0, NIST IR 8547), and regulatory gates for NTIA, FDA, EU CRA, BSI TR-03183, EUCC, SSDF, EO 14028, and the EU AI Act.
☆238Aug 1, 2026Updated this week
Alternatives and similar repositories for sbom-tools
Users that are interested in sbom-tools are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- CI/CD supply chain hardening plugin for Claude Code, designed for Rust projects☆15Mar 22, 2026Updated 4 months ago
- Repository of AI skills specific to CycloneDX☆31Apr 16, 2026Updated 3 months ago
- Data for CyberSOCEval, an LLM benchmark by Meta & CrowdStrike☆21Sep 22, 2025Updated 10 months ago
- Vulnerability detection framework by Binarly's REsearch team☆872Jul 22, 2026Updated 2 weeks ago
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆29Jul 6, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- SymRustC is a hybrid fuzzer for Rust combining concolic execution using SymCC and fuzzing using LibAFL.☆11Jun 28, 2023Updated 3 years ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆169Updated this week
- AI Guided Hybrid Application Static Testing☆83Updated this week
- executing shellcode directly from a python variable☆30Dec 20, 2025Updated 7 months ago
- An query language and interactive tooling to work with SBOM data.☆15Oct 7, 2024Updated last year
- A curated list of Ransomware resources☆40May 11, 2026Updated 2 months ago
- Fuzzers implemented with libafl to evaluate several techniques on fuzzbench☆12Oct 10, 2024Updated last year
- GitHub Action to alert on security patches before the CVE drops.☆216Updated this week
- Supply Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆381Jul 20, 2026Updated 2 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Privateer is a plugin-based framework for security & compliance evaluations.☆23Jul 27, 2026Updated last week
- ☆55Jun 13, 2026Updated last month
- Performance monitoring agent for eBPF programs☆18Updated this week
- Library for manipulating gdb in batch mode☆21Mar 10, 2024Updated 2 years ago
- Format agnostic SBOM tooling☆155Nov 20, 2025Updated 8 months ago
- GRC Engineer Directory☆17Updated this week
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆374Updated this week
- Sydr benchmark applications☆17Jul 25, 2022Updated 4 years ago
- Helping defenders learn and validate npm supply-chain detections with safe atomic tests.☆34Oct 30, 2025Updated 9 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆22May 28, 2026Updated 2 months ago
- Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-kno…☆21Jul 24, 2026Updated last week
- MCP to help Defenders Detection Engineer Harder and Smarter☆467Jun 16, 2026Updated last month
- Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streaml…☆555Updated this week
- Code canaries to quickly triage hallucinated ('slop') vulnerability reports☆96May 20, 2026Updated 2 months ago
- Tailscale/Headscale C2 profile and agent for Mythic☆25Mar 14, 2026Updated 4 months ago
- Fuzzing Lua runtimes without pain☆16Updated this week
- ☆13Apr 24, 2023Updated 3 years ago
- Tool for visualizing the Open SSF Scorecard Api data in a human friendly way☆20Jul 28, 2026Updated last week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- PoC shadow SaaS and insecure credential detection system using a browser extension.☆45Updated this week
- A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.☆176Jul 29, 2026Updated last week
- A vibe-coded port of wiretap☆36Apr 25, 2026Updated 3 months ago
- A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE☆117Updated this week
- AI model safety scanner built on NVIDIA garak☆635Updated this week
- Aggregate vulnerability scans from multiple container image scanners to identify discrepancies and get comprehensive exposure analysis.☆85Jul 10, 2026Updated 3 weeks ago
- Sunshine - SBOM visualization tool☆119May 17, 2026Updated 2 months ago