#sbom (25 Repositories)
Ranked open-source repositories tagged with #sbom, scored by pull request acceptance likelihood and maintainer engagement velocity.
45.7%
24.4h
25 repositories tagged #sbom
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
anchore/grant
A license scanner for container images and filesystems.
CycloneDX/cyclonedx-gomod
Creates CycloneDX Software Bill of Materials (SBOM) from Go modules
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
relizaio/rearm
ReARM - Release Governance Platform
interlynk-io/sbomqs
sbomqs: The Comprehensive SBOM Quality & Compliance Tool
CycloneDX/cyclonedx-core-java
CycloneDX SBOM Model and Utils for Creating and Validating BOMs
CycloneDX/cyclonedx-gradle-plugin
Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects
konflux-ci/konflux-ci
Trusted builds made easy! A cloud-native software factory for building, testing, and releasing trusted software artifacts
ckotzbauer/sbom-operator
Catalogue all images of a Kubernetes cluster to multiple targets with Syft
kdeldycke/meta-package-manager
🎁 snapshot every package on your machine to one file, restore it on a new one
microsoft/component-detection
Scans your project to determine what components you use
anchore/syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
CycloneDX/specification
OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and VEX
guacsec/guac
GUAC aggregates software security metadata into a high fidelity graph database.
CycloneDX/cyclonedx-go
Go library to consume and produce CycloneDX Software Bill of Materials (SBOM)
interlynk-io/sbomasm
sbomasm: The Complete SBOM Management Toolkit
kubernetes-sigs/bom
A utility to generate SPDX-compliant Bill of Materials manifests
aboutcode-org/aboutcode
AboutCode project: tools and data to uncover things about code: the provenance, origin, license, and more (packages, security, quality, etc.) of FOSS code. Get started at https://aboutcode.readthedocs.io/
fsfe/reuse-tool
This is a mirror of https://codeberg.org/fsfe/reuse-tool
snyk/parlay
Enrich SBOMs with data from third party services
spdx/spdx-spec
The System Package Data Exchange (SPDX) specification in Markdown and HTML formats.
xeol-io/xeol
A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs
cbomkit/cbomkit
A toolset for dealing with Cryptography Bill of Materials (CBOM)