software-composition-analysis topic
OpenSCA-cli
OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the...
actions-all-in-one
All of our GitHub Actions rolled into one. Or as we like to say: One GitHub Action to rule them all!
actions-log4j
A GitHub Action that scans your public web applications for log4j vulnerabilities after every deployment. Add this to your dev, staging and prod steps and SecureStack will make sure that what you've j...
awesome-software-supply-chain-security
Sharing software supply chain security open source projects
vet
Tool to achieve policy driven vetting of open source dependencies
sbom-workbench
The SCANOSS SBOM Workbench graphical user interface to scan and audit your source code.
cyclonedx-go
Creates CycloneDX Software Bill-of-Materials (SBOM) from Go projects. So you can use it with DependencyTrack to monitor security issues in 3rd party modules.
scanoss.py
The SCANOSS python package providing a simple, easy to consume library for interacting with SCANOSS APIs/Engine.
DevSecOps
♾️ Collection of DevSecOps Notes + Resources + Courses + Tools
meta-dependencytrack
A Yocto meta-layer for generating CycloneDX SBOMs and automatically uploading them to Dependency Track.