Repository navigation

#

sbom-generator

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

JavaScript
3981
4 天前

The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.

C#
1903
2 天前

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

TypeScript
1457
1 年前

A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles

540
4 个月前

CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.

C#
410
5 天前

A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.

Python
372
3 天前

Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects

Java
335
10 天前

CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments

Python
332
4 天前

Creates CycloneDX Software Bill of Materials (SBOM) from .NET Projects

C#
237
1 个月前

Creates CycloneDX Software Bill of Materials (SBOM) from Go modules

Go
162
2 天前

Creates CycloneDX Software Bill of Materials (SBOM) from Rust (Cargo) projects

Rust
143
4 天前

creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects

134
19 天前

Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.

JavaScript
103
4 天前

sbomasm: The Complete SBOM Management Toolkit

Go
86
7 天前

Compage - Low-Code Framework to develop Rest API, gRPC, dRPC, GraphQL, WebAssembly, microservices, FaaS, Temporal workloads, IoT and edge services, K8s controllers, K8s CRDs, K8s custom APIs, K8s Operators, K8s hooks, etc. with minimal coding and by automatically applying best practice methods like software supply chain security measures, SBOM, openAPI, cloudevents, etc. Auto generate code after defining requirements in UI as diagram.

Go
85
1 年前

Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security, vulnerability, insecure infrastructure as code, and potential legal issues with open source licenses.

TypeScript
78
1 年前