snyk-tech-services / snyk2spdx
☆13Updated last year
Related projects ⓘ
Alternatives and complementary repositories for snyk2spdx
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆58Updated last year
- Trivy plugin for OCI referrers☆21Updated 6 months ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- Scans SBOMs for vulnerabilities with Grype☆79Updated last week
- Fairwinds Base Image Finder CLI☆34Updated this week
- Grype vulnerability check plugin for Visual Studio Code☆22Updated 2 months ago
- ☆14Updated last year
- ☆61Updated 4 months ago
- `yorbox` is a command-line interface (CLI) tool that helps manage tags consistently across infrastructure as code (IaC) frameworks. It is…☆31Updated last week
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- SPDX Merge tool☆39Updated 2 months ago
- A tool to create, transform and attest VEX metadata☆119Updated this week
- Go client library for OWASP Dependency-Track☆22Updated 2 weeks ago
- Trust Dexter to ensure that all your images are pinned by digest for better security☆29Updated last year
- Check images in your charts for vulnerabilities☆41Updated last year
- Kubernetes audit logging, when you don't control the control plane☆65Updated this week
- Enrich SBOMs with data from third party services☆121Updated this week
- Proof-of-concept SLSA provenance generator for GitHub Actions☆99Updated 2 years ago
- Utility that provides an API and CLI to identify licenses and legal terms☆43Updated 5 months ago
- A BOM repository server for distributing CycloneDX BOMs☆74Updated 8 months ago
- A VS Code Extension for Trivy☆116Updated last year
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Anchore Kubernetes Inventory can poll Kubernetes Cluster API(s) to tell Anchore Enterprise which Containers and Images are currently in-u…☆63Updated this week
- Slack alert bot for matching Github Audit Events☆10Updated last week
- Plugin for retrieving Dependencytrack metrics in Backstage☆16Updated 2 months ago
- An SBOM query language and associated utilities☆54Updated 10 months ago
- Count distinct contributor of Snyk watched repos across several SCM☆30Updated 4 months ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆76Updated this week
- Runtime security plug to protect user containers☆65Updated this week