sbomtools / apt2sbom
apt2sbom python package generates SPDX or CycloneDX files from Ubuntu APT and Python packaging information
☆22Updated 3 years ago
Alternatives and similar repositories for apt2sbom:
Users that are interested in apt2sbom are comparing it to the libraries listed below
- A CVRF CSAF Converter, taking care about OASIS specification.☆10Updated last month
- Lockheed Martin developed utility to generate CycloneDX SBOMs for Linux distributions☆42Updated 9 months ago
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- ☆100Updated 4 months ago
- ☆47Updated this week
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- Utility that provides an API platform for validating, querying and managing BOM data☆102Updated 2 months ago
- Posture Attribute Collection and Evaluation☆24Updated last year
- VINCE is the Vulnerability Information and Coordination Environment developed and used by the CERT Coordination Center to improve coordin…☆60Updated this week
- Sharing software supply chain security open source projects☆44Updated 2 years ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆62Updated this week
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆83Updated last week
- SPDX Merge tool☆40Updated 5 months ago
- Library to ingest and generate SBOMs☆22Updated last month
- Automating Compliance Tooling Project☆20Updated 3 years ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆71Updated this week
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- OASIS CSAF TC: Supporting version control for Work Product artifacts developed by members of TC, including prose specifications and secon…☆158Updated this week
- Format agnostic SBOM tooling☆97Updated this week
- Stakeholder-Specific Vulnerability Categorization☆136Updated this week
- Low-effort reachability analysis for third-party code vulnerabilities.☆20Updated last year
- Service to scan licenses from source code☆12Updated last year
- Secvisogram is a web tool for creating and editing security advisories in the CSAF 2.0 format☆36Updated this week
- OpenVEX Specification☆141Updated 7 months ago
- Potential WG on Artificial Intelligence and Machine Learning (AI/ML)☆60Updated 3 months ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆78Updated this week
- OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Is…☆56Updated 3 weeks ago
- Utility that converts SBOM documents from CycloneDX to SPDX☆29Updated last year
- Tools to download or provide CSAF (Common Security Advisory Framework) documents.☆42Updated last week