Repository navigation

#

spdx

anchore/syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Go
6844
3 天前

🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase, the Google Summer of Code, Azure credits, nexB and others generous sponsors!

Python
2264
2 天前

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.

Go
1065
6 天前

Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.

Python
982
1 年前

FOSSology is an open source license compliance software system and toolkit. As a toolkit you can run license, copyright and export control scans from the command line. As a system, a database and web ui are provided to give you a compliance workflow. License, copyright and export scanners are tools used in the workflow.

HTML
851
2 天前

A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby

761
4 天前

📜 Cargo plugin to generate list of all licenses for a crate 🦀

Rust
590
1 个月前

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

Go
561
20 天前

Various data formats for the SPDX License List including RDFa, HTML, Text, and JSON

HTML
558
2 天前

reuse is a tool for compliance with the REUSE recommendations.

Python
467
4 天前

Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more

Go
424
4 天前

OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and VEX

XSLT
395
3 天前

A utility to generate SPDX-compliant Bill of Materials manifests

Go
381
6 天前

CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.

C#
351
5 个月前

Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects

Java
320
2 天前

The System Package Data Exchange (SPDX) specification in Markdown and HTML formats.

Python
318
1 天前

CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments

Python
276
6 天前