#spdx (13 Repositories)
Ranked open-source repositories tagged with #spdx, scored by pull request acceptance likelihood and maintainer engagement velocity.
51.4%
145.1h
13 repositories tagged #spdx
opossum-tool/OpossumUI
A light-weight app to audit and inventory large codebases for open source license compliance.
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
interlynk-io/sbomqs
sbomqs: The Comprehensive SBOM Quality & Compliance Tool
CycloneDX/specification
OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and VEX
CycloneDX/cyclonedx-core-java
CycloneDX SBOM Model and Utils for Creating and Validating BOMs
CycloneDX/cyclonedx-gradle-plugin
Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects
anchore/syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
CycloneDX/cyclonedx-dotnet
Creates CycloneDX Software Bill of Materials (SBOM) from .NET Projects
hashicorp/copywrite
Automate copyright headers and license files at scale
spdx/spdx-spec
The System Package Data Exchange (SPDX) specification in Markdown and HTML formats.
fsfe/reuse-tool
This is a mirror of https://codeberg.org/fsfe/reuse-tool
kubernetes-sigs/bom
A utility to generate SPDX-compliant Bill of Materials manifests