scanoss / engine
SCANOSS Open Source Inventory Engine
☆38Updated last month
Alternatives and similar repositories for engine:
Users that are interested in engine are comparing it to the libraries listed below
- SCANOSS Mining tool☆22Updated 4 months ago
- The SCANOSS python package providing a simple, easy to consume library for interacting with SCANOSS APIs/Engine.☆31Updated last week
- The SCANOSS SBOM Workbench graphical user interface to scan and audit your source code.☆50Updated this week
- Utility that converts SBOM documents from CycloneDX to SPDX☆28Updated last year
- The model for the information captured in SPDX version 3 standard.☆81Updated this week
- This tool compares two Software Bill of Materials (SBOMs) and reports the differences.☆31Updated 5 months ago
- PURL to CPE Relationship mapping project.☆86Updated this week
- This is a mapping of CPEs to package urls created by using VulnerableCode's data☆9Updated 4 years ago
- Check SPDX SBOM for NTIA minimum elements☆62Updated 2 weeks ago
- OSS License Open Data☆12Updated 5 years ago
- Parse and compare all the package versions and all the ranges. From debian, npm, pypi, ruby and more. Process all the version range specs…☆35Updated 6 months ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆92Updated last week
- A collection of scripts for license compliance scanning, mostly experimental☆22Updated 2 months ago
- SBOM Assembler - A tool to edit SBOM or assemble multiple sboms into a single sbom.☆69Updated this week
- SPDX Merge tool☆43Updated last month
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and o…☆75Updated 3 weeks ago
- Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulner…☆45Updated this week
- OSADL license compatibility matrix as a CSV☆16Updated 4 months ago
- Find & pull public SBOMs☆18Updated 7 months ago
- Examples of SPDX files for software combinations☆129Updated last week
- A light-weight app to audit and inventory large codebases for open source license compliance.☆64Updated this week
- Produce an Open Source Vulnerability JSON file based on information in an SPDX document☆64Updated 10 months ago
- A place to systematically store software bill of materials (SBOM) documents.☆46Updated last year
- Sharing software supply chain security open source projects☆48Updated 2 years ago
- SARIF Microsoft Visual Studio Code extension☆114Updated this week
- A Yocto meta-layer for generating CycloneDX SBOMs and automatically uploading them to Dependency Track.☆20Updated 10 months ago
- Automating Compliance Tooling Project☆21Updated 3 years ago
- Service to scan licenses from source code☆12Updated last year
- A standard API specification for exchanging supply chain artifacts and intelligence☆78Updated this week
- List of SBOM Generation Tools☆23Updated last month