xeol-io / xeol
A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs
☆388Updated this week
Alternatives and similar repositories for xeol:
Users that are interested in xeol are comparing it to the libraries listed below
- Evaluate source control (GitHub) security posture☆249Updated 2 years ago
- Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more☆424Updated this week
- A security layer for Git repositories☆503Updated this week
- Open source compliance tool for development platforms.☆286Updated last year
- Inspect certificate authorities in container images☆233Updated this week
- Enrich SBOMs with data from third party services☆167Updated 2 weeks ago
- boostsecurityio/poutine☆264Updated this week
- Software Supply Chain Security Platform☆329Updated this week
- 🚀 Policy driven vetting of open source packages with malicious code analysis☆333Updated this week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆448Updated this week
- Verify provenance from SLSA compliant builders☆254Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆228Updated 8 months ago
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆800Updated 3 weeks ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆187Updated this week
- A utility to generate SPDX-compliant Bill of Materials manifests☆381Updated last week
- Notice: Postee is no longer under active development or maintenance.☆210Updated last week
- A universal SBOM representation in protocol buffers☆281Updated last week
- Search an SBOM for licenses and the packages they belong to☆84Updated this week
- KBOM - Kubernetes Bill of Materials☆313Updated last month
- Chalk allows you to follow code from development, through builds and into production.☆371Updated this week
- SecObserve is an open source vulnerability and license management system for software development teams and cloud environments. It suppor…☆131Updated this week
- OpenVEX Specification☆144Updated 3 weeks ago
- Validate the isolation posture of your container environment.☆272Updated this week
- BadRobot - Operator Security Audit Tool☆219Updated this week
- By scanning CI/CD misconfigurations, Allero helps reduce production issues, harden your security posture and shift-left CI/CD from DevOps…☆205Updated last year
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆561Updated 2 weeks ago
- Language-agnostic SLSA provenance generation for Github Actions☆460Updated last month
- Runtime Security Solution for your CI/CD Pipeline☆101Updated last month
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆314Updated last year
- A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles☆510Updated 5 months ago