software-composition-analysis topic

List software-composition-analysis repositories

lunasec

1.4k
Stars
162
Forks
Watchers

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTra...

scancode.io

109
Stars
85
Forks
Watchers

ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabas...

awesome-sca

90
Stars
29
Forks
Watchers

A curated list of Software Component Analysis (SCA) books, courses - free and paid, videos, tools, and tutorials.

awesome-software-supply-chain-security

279
Stars
26
Forks
Watchers

A compilation of resources in the software supply chain security domain, with emphasis on open source

actions-exposure

22
Stars
5
Forks
Watchers

A GitHub Action that scans your public web applications after every deployment. Add this to your dev, staging and prod steps and SecureStack will make sure that what you've just deployed is secure an...

dependency-track-maven-plugin

61
Stars
19
Forks
Watchers

Maven plugin that integrates with a Dependency Track server to submit dependency manifests and optionally fail execution when vulnerable dependencies are found.

OpossumUI

55
Stars
25
Forks
Watchers

A light-weight app to audit and inventory large codebases for open source license compliance.

actions-code

21
Stars
3
Forks
Watchers

A GitHub Action for using SecureStack to analyse a repository codebase for vulnerabilities in library dependencies (software composition analysis).

dependency-check-py

48
Stars
12
Forks
Watchers

:closed_lock_with_key: Shim to easily install OWASP dependency-check-cli into Python projects

dtrack-audit

47
Stars
14
Forks
Watchers

OWASP Dependency Track API client for intergration into CI/CD pipeline