software-composition-analysis topic

List software-composition-analysis repositories

OpenSCA-cli

1.0k
Stars
116
Forks
Watchers

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the...

actions-all-in-one

20
Stars
6
Forks
Watchers

All of our GitHub Actions rolled into one. Or as we like to say: One GitHub Action to rule them all!

actions-log4j

15
Stars
2
Forks
Watchers

A GitHub Action that scans your public web applications for log4j vulnerabilities after every deployment. Add this to your dev, staging and prod steps and SecureStack will make sure that what you've j...

Sharing software supply chain security open source projects

vet

183
Stars
16
Forks
Watchers

Tool to achieve policy driven vetting of open source dependencies

sbom-workbench

41
Stars
9
Forks
Watchers

The SCANOSS SBOM Workbench graphical user interface to scan and audit your source code.

cyclonedx-go

20
Stars
3
Forks
Watchers

Creates CycloneDX Software Bill-of-Materials (SBOM) from Go projects. So you can use it with DependencyTrack to monitor security issues in 3rd party modules.

scanoss.py

23
Stars
17
Forks
Watchers

The SCANOSS python package providing a simple, easy to consume library for interacting with SCANOSS APIs/Engine.

DevSecOps

54
Stars
4
Forks
Watchers

♾️ Collection of DevSecOps Notes + Resources + Courses + Tools

meta-dependencytrack

15
Stars
18
Forks
Watchers

A Yocto meta-layer for generating CycloneDX SBOMs and automatically uploading them to Dependency Track.