sbom topic
meta-package-manager
🎁 wraps all package managers with a unifying CLI
sbom-operator
Catalogue all images of a Kubernetes cluster to multiple targets with Syft
vulnerability-operator
Scans SBOMs for vulnerabilities with Grype
scancode-toolkit
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nl...
lunasec
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTra...
it-depends
A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.
zarf
DevSecOps for Air Gap & Limited-Connection Systems. https://zarf.dev/
dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
tern
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-...
ort
A suite of tools to automate software compliance checks.