awesome-sbom icon indicating copy to clipboard operation
awesome-sbom copied to clipboard

A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles

Results 9 awesome-sbom issues
Sort by recently updated
recently updated
newest added

OpenSCA-cli supports generating SBOMs in CycloneDX, SPDX, SWID formats through package manager information, and also supports analyzing the above SBOMs as input, or converting them to other SBOM formats. I...

Potential video to add from OWASPMcr / Anthony Harrison: https://youtu.be/COi7fTmix7U?si=fvgAWBwfGiBkwM6R

Google osv-scanner is a dependency vulnerability scanner that supports SBOM: https://google.github.io/osv-scanner/usage/

By using a legend of short glyphs (🌀 = CycloneDX, 💨 = SPDX, ...) and using them in the cells, you could make the columns thinner and thus avoid the...

Added links to their desktop application and Python CLI tool.

NTIA has debated categorizing toling along the lines of - Produce / Consume and Transform https://ntia.gov/sites/default/files/publications/ntia_sbom_tooling_taxonomy-2021mar30_0.pdf I am happy to put together changes to the awesomeSBOM based on that categorization...

update DeepSCA supported formats and add a blog discussing accuracy of current SBOM generation tools.