Semantic SBOM/CBOM/AI-BOM diff, quality scoring, and compliance validation for CycloneDX/SPDX — component, license, and vulnerability change analysis, cryptographic inventory grading, PQC readiness (CNSA 2.0, NIST IR 8547), and regulatory gates for NTIA, FDA, EU CRA, BSI TR-03183, EUCC, SSDF, EO 14028, and the EU AI Act.
☆239Aug 20, 2026Updated last week
Alternatives and similar repositories for sbom-tools
Users that are interested in sbom-tools are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- CI/CD supply chain hardening plugin for Claude Code, designed for Rust projects☆15Mar 22, 2026Updated 5 months ago
- Repository of AI skills specific to CycloneDX☆31Apr 16, 2026Updated 4 months ago
- Data for CyberSOCEval, an LLM benchmark by Meta & CrowdStrike☆23Sep 22, 2025Updated 11 months ago
- Vulnerability detection framework by Binarly's REsearch team☆880Updated this week
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆30Jul 6, 2026Updated last month
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- SymRustC is a hybrid fuzzer for Rust combining concolic execution using SymCC and fuzzing using LibAFL.☆11Jun 28, 2023Updated 3 years ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆178Aug 16, 2026Updated last week
- AI Guided Hybrid Application Static Testing☆86Aug 3, 2026Updated 3 weeks ago
- executing shellcode directly from a python variable☆30Dec 20, 2025Updated 8 months ago
- An query language and interactive tooling to work with SBOM data.☆15Oct 7, 2024Updated last year
- A curated list of Ransomware resources☆40May 11, 2026Updated 3 months ago
- Fuzzers implemented with libafl to evaluate several techniques on fuzzbench☆12Oct 10, 2024Updated last year
- GitHub Action to alert on security patches before the CVE drops.☆217Aug 17, 2026Updated last week
- Supply Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆385Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Privateer is a plugin-based framework for security & compliance evaluations.☆24Updated this week
- Performance monitoring agent for eBPF programs☆18Aug 17, 2026Updated last week
- Library for manipulating gdb in batch mode☆21Aug 9, 2026Updated 2 weeks ago
- Format agnostic SBOM tooling☆156Nov 20, 2025Updated 9 months ago
- GRC Engineer Directory☆17Updated this week
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆375Aug 6, 2026Updated 3 weeks ago
- Sydr benchmark applications☆17Jul 25, 2022Updated 4 years ago
- Helping defenders learn and validate npm supply-chain detections with safe atomic tests.☆34Oct 30, 2025Updated 9 months ago
- ☆22May 28, 2026Updated 2 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-kno…☆25Jul 24, 2026Updated last month
- Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.☆91Updated this week
- MCP to help Defenders Detection Engineer Harder and Smarter☆474Jun 16, 2026Updated 2 months ago
- Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streaml…☆566Updated this week
- Code canaries to quickly triage hallucinated ('slop') vulnerability reports☆97May 20, 2026Updated 3 months ago
- Tailscale/Headscale C2 profile and agent for Mythic☆34Mar 14, 2026Updated 5 months ago
- Fuzzing Lua runtimes without pain☆16Aug 4, 2026Updated 3 weeks ago
- ☆13Apr 24, 2023Updated 3 years ago
- Tool for visualizing the Open SSF Scorecard Api data in a human friendly way☆20Aug 11, 2026Updated 2 weeks ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- PoC shadow SaaS and insecure credential detection system using a browser extension.☆45Aug 5, 2026Updated 3 weeks ago
- A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.☆177Jul 29, 2026Updated 3 weeks ago
- A vibe-coded port of wiretap☆36Apr 25, 2026Updated 4 months ago
- A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE☆118Aug 10, 2026Updated 2 weeks ago
- AI model safety scanner built on NVIDIA garak☆653Updated this week
- Aggregate vulnerability scans from multiple container image scanners to identify discrepancies and get comprehensive exposure analysis.☆85Jul 10, 2026Updated last month
- Sunshine - SBOM visualization tool☆120May 17, 2026Updated 3 months ago