sonatype-nexus-community / ahab
ahab is a tool to check for vulnerabilities in your apt, apk, or yum powered operating systems, powered by Sonatype OSS Index.
☆67Updated last year
Alternatives and similar repositories for ahab:
Users that are interested in ahab are comparing it to the libraries listed below
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Updated last year
- ☆29Updated this week
- Grype vulnerability check plugin for Visual Studio Code☆22Updated 4 months ago
- Publishes BOMs to Dependency-Track from GitHub Actions☆53Updated 6 months ago
- in-toto is a framework to secure the software supply chain.☆70Updated 3 months ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 2 months ago
- vexctl is a tool to attest VEX impact statements☆44Updated 2 years ago
- Specification and other related documents.☆45Updated 3 months ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆99Updated 2 years ago
- a tool to audit the istio service mesh☆173Updated 3 years ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- Technical Advisory Council☆122Updated last week
- A BOM repository server for distributing CycloneDX BOMs☆77Updated last year
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- Open Source Vulnerability schema.☆198Updated 2 weeks ago
- The Auditree framework tool to run compliance control checks as unit tests.☆63Updated 8 months ago
- Slack alert bot for matching Github Audit Events☆10Updated 5 months ago
- OpenVEX Specification☆145Updated 3 weeks ago
- GKE CIS 1.1.0 Benchmark InSpec Profile☆27Updated 3 years ago
- Securing Alice's, Bob's and Carl's software supply chain using in-toto☆92Updated last month
- A standard API specification for exchanging supply chain artifacts and intelligence☆78Updated last week
- ☆29Updated 2 months ago
- Runtime security plug to protect user containers☆65Updated 2 months ago
- An SBOM query language and associated utilities☆54Updated last year
- An query language and interactive tooling to work with SBOM data.☆14Updated 6 months ago
- Terraform module to configure Vault for GitHub OIDC authentication from Action runners.☆29Updated 8 months ago
- Security scanning & static analysis tool☆94Updated 6 months ago
- A specification for signing methods and formats used by Secure Systems Lab projects.☆75Updated 7 months ago