Projects in Awesome Lists tagged with sbom
A curated list of projects in awesome lists tagged with sbom .
https://github.com/anchore/syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
containers cyclonedx docker go golang hacktoberfest oci sbom spdx static-analysis tool
Last synced: 12 May 2025
https://retirejs.github.io/retire.js/
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
build-tool chrome-extension firefox-extension grunt-plugins insecure-libraries javascript sbom sbom-generator sbom-tool scanner security software-composition-analysis vulnerabilities vulnerable-libraries
Last synced: 21 Nov 2025
https://github.com/retirejs/retire.js
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
build-tool chrome-extension firefox-extension grunt-plugins insecure-libraries javascript sbom sbom-generator sbom-tool scanner security software-composition-analysis vulnerabilities vulnerable-libraries
Last synced: 18 Jan 2026
https://github.com/dependencytrack/dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
appsec bill-of-materials bom component-analysis cyclonedx devsecops hacktoberfest nvd ossindex owasp package-url purl sbom sca security security-automation software-composition-analysis software-security vulnerabilities vulnerability-detection
Last synced: 12 Jun 2026
https://github.com/RetireJS/retire.js
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
build-tool chrome-extension firefox-extension grunt-plugins insecure-libraries javascript sbom sbom-generator sbom-tool scanner security software-composition-analysis vulnerabilities vulnerable-libraries
Last synced: 26 Mar 2025
https://github.com/DependencyTrack/dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
appsec bill-of-materials bom component-analysis cyclonedx devsecops hacktoberfest nvd ossindex owasp package-url purl sbom sca security security-automation software-composition-analysis software-security vulnerabilities vulnerability-detection
Last synced: 30 Mar 2025
https://github.com/e-m-b-a/emba
EMBA - The firmware security analyzer
artificial-intelligence binary-analysis embedded-linux embedded-systems firmware firmware-analysis firmware-tools hacking infosec iot linux penetration-testing pentesting reverse-engineering sbom security security-tools static-analyzer vulnerability-scanner vulnerability-scanners
Last synced: 14 May 2025
https://github.com/aboutcode-org/scancode-toolkit
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase, the Google Summer of Code, Azure credits, nexB and others generous sponsors!
copyright copyright-scan cyclonedx dependencies dependency-graph license license-checking license-scan licensing open-source-licensing oss-compliance package-url packages provenance purl sbom sca software-composition-analysis spdx spdx-licenses
Last synced: 11 May 2025
https://github.com/zarf-dev/zarf
The Airgap Native Package Manager for Kubernetes
airgap cloud-native cosign docker docker-registry dod gitops government hacktoberfest helm k3s k8s kubernetes kustomize oci sbom
Last synced: 20 May 2026
https://github.com/HummerRisk/HummerRisk
HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。
cloud-custodian cloud-native cloud-native-security compliance compliance-as-code cspm k8s-security kubernetes-security prowler sbom security trivy vulnerability
Last synced: 01 May 2025
https://github.com/microsoft/sbom-tool
The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.
Last synced: 12 May 2025
https://github.com/oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
compliance copyright cra cyclonedx dependencies dependency-graph dora hacktoberfest license license-management open-source-licensing ospo oss-compliance package-manager sbom sbom-generator sca spdx
Last synced: 23 Apr 2026
https://github.com/ossf/cve-bin-tool
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
cve cvss devsecops hacktoberfest python sbom sbom-tool security security-automation security-tools swrepo system-tools vulnerabilities vulnerability
Last synced: 03 Mar 2026
https://github.com/hummerrisk/hummerrisk
HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。
cloud-custodian cloud-native cloud-native-security compliance compliance-as-code cspm k8s-security kubernetes-security prowler sbom security trivy vulnerability
Last synced: 14 May 2025
https://github.com/lunasec-io/lunasec
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
compliance continuous-delivery cve-scanning cybersecurity dependency-analysis devsecops gdpr log4shell pci-dss sbom sbom-generator scanning scanning-tool security security-tools soc2 software-composition-analysis tokenization web-security zero-trust
Last synced: 15 May 2025
https://github.com/intel/cve-bin-tool
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
cve cvss devsecops hacktoberfest python sbom sbom-tool security security-automation security-tools swrepo system-tools vulnerabilities vulnerability
Last synced: 13 May 2025
https://github.com/guacsec/guac
GUAC aggregates software security metadata into a high fidelity graph database.
attestations cyclonedx cyclonedx-sbom graph in-toto sbom security slsa software-supply-chain software-supply-chain-security spdx spdx-sbom supply-chain supply-chain-analytics supply-chain-security supply-chain-visibility vex vulnerability vulnerability-management
Last synced: 14 May 2025
https://github.com/openclarity/openclarity
OpenClarity is an open source tool built to enhance security and observability of cloud native applications and infrastructure
cloud exploits kubernetes leaked-secrets malware rootkits sbom scanner security supply-chain virtual-machine vulnerabilities
Last synced: 15 Dec 2025
https://github.com/owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
compliance containers cve cyclonedx dependency-analysis dependency-audit devsecops reachability-analysis risk-audit sbom sca security-audit security-tools supply-chain-security vex vulnerability-scanners
Last synced: 08 May 2026
https://github.com/xmirrorsecurity/opensca-cli
OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
cyclonedx devsecops license-compliance sbom sca security software-bill-of-materials software-composition-analysis software-supply-chain software-supply-chain-security spdx static-analysis swid vulnerabilities
Last synced: 14 May 2025
https://github.com/XmirrorSecurity/OpenSCA-cli
OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
cyclonedx devsecops license-compliance sbom sca security software-bill-of-materials software-composition-analysis software-supply-chain software-supply-chain-security spdx static-analysis swid vulnerabilities
Last synced: 26 Apr 2025
https://github.com/tern-tools/tern
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
compliance containers dependencies docker metadata-extraction open-source oss-compliance python risk-management sbom software-composition-analysis spdx supply-chain-security tool
Last synced: 15 May 2025
https://github.com/cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
bom cbom containers cyclonedx docker oci owasp package-url purl saasbom sbom sca software-bill-of-materials supply-chain
Last synced: 23 May 2026
https://github.com/package-url/purl-spec
A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby
cyclonedx dependencies package package-management package-url purl sbom spdx url
Last synced: 10 Oct 2025
https://github.com/rust-secure-code/cargo-auditable
Make production Rust binaries auditable
cargo-plugin cargo-subcommand rust rust-lang sbom security-audit security-automation security-tools
Last synced: 18 May 2026
https://github.com/bitbomdev/minefield
Graphing SBOM's Fast.
ai airgap graph llm roaring-bitmaps sbom supply-chain-security
Last synced: 14 Mar 2025
https://github.com/cyclonedx/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server. GPT: https://chatgpt.com/g/g-673bfeb4037481919be8a2cd1bf868d2-cdxgen
bom cbom containers cyclonedx docker oci owasp package-url purl saasbom sbom sca software-bill-of-materials supply-chain
Last synced: 13 Apr 2025
https://github.com/CycloneDX/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server. GPT: https://chatgpt.com/g/g-673bfeb4037481919be8a2cd1bf868d2-cdxgen
bom cbom containers cyclonedx docker oci owasp package-url purl saasbom sbom sca software-bill-of-materials supply-chain
Last synced: 01 Apr 2025
https://github.com/arpsyndicate/puncia
Panthera(P.)uncia - Official CLI utility for Osprey Vision, Subdomain Center & Exploit Observer.
arpsyndicate cyclonedx cyclonedx-sbom exploit sbom sbom-tool subdomain vulnerability
Last synced: 14 May 2025
https://github.com/ARPSyndicate/puncia
Panthera(P.)uncia - Official CLI utility for Osprey Vision, Subdomain Center & Exploit Observer.
arpsyndicate cyclonedx cyclonedx-sbom exploit sbom sbom-tool subdomain vulnerability
Last synced: 05 Apr 2025
https://github.com/devops-kung-fu/bomber
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
cyclonedx devsecops epss golang gomodule oss sbom security security-automation security-tools spdx supply-chain supplychain syft vulnerability-scanners
Last synced: 15 May 2025
https://github.com/kdeldycke/meta-package-manager
🎁 wraps all package managers with a unifying CLI
apt cyclonedx flatpak homebrew linux mac-app-store macos npm package-manager package-url php-composer pip ruby-gem sbom snap spdx steam windows xbar yarn
Last synced: 02 Apr 2026
https://github.com/chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
attestation compliance cyclonedx devsecops in-toto license metadata-platform open-source-licensing ospo oss-compliance regulated-industry sbom sbom-discovery sbom-distribution security slsa slsa-provenance spdx supply-chain-security
Last synced: 01 May 2026
https://github.com/microsoft/component-detection
Scans your project to determine what components you use
dependencies package-management sbom software-bill-of-materials software-composition-analysis static-analysis
Last synced: 14 Apr 2026
https://github.com/sandworm-hq/sandworm-audit
Security & License Compliance For Your App's Dependencies 🪱
audit cli compliance d3-visualization dependencies dependencies-graph dependencies-tree license-checking license-compliance license-management sbom security security-tools supply-chain vulnerabilities vulnerability vulnerability-scanners
Last synced: 15 Apr 2025
https://github.com/xeol-io/xeol
A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs
compliance end-of-life eol fedramp nist outdated-dep outdated-libraries outdated-packages pci-dss release-policy sbom security
Last synced: 22 Aug 2026
https://github.com/noqcks/xeol
A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs
compliance end-of-life eol fedramp nist outdated-dep outdated-libraries outdated-packages pci-dss release-policy sbom security
Last synced: 13 May 2025
https://github.com/cyclonedx/specification
OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and VEX
bill-of-materials bom cbom cpe cyclonedx license machine-learning mbom owasp saasbom sbom software software-bill-of-materials spdx specification standard supply-chain swid tc54 vex
Last synced: 10 Feb 2026
https://github.com/owasp-dep-scan/blint
BLint is a Binary Linter to check the security properties, and capabilities in your executables. Since v2, blint is also an SBOM generator for binaries.
binary cyclonedx depscan fuzzing malware sbom supply-chain-analytics supply-chain-security
Last synced: 03 Mar 2026
https://github.com/CycloneDX/specification
OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and VEX
bill-of-materials bom cbom cpe cyclonedx license machine-learning mbom owasp saasbom sbom software software-bill-of-materials spdx specification standard supply-chain swid tc54 vex
Last synced: 08 May 2025
https://github.com/trailofbits/it-depends
A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.
dependency-analysis dependency-graph hacktoberfest hacktoberfest2021 sbom sbom-generator vulnerability-scanner
Last synced: 15 May 2025
https://github.com/kubernetes-sigs/bom
A utility to generate SPDX-compliant Bill of Materials manifests
bom go golang kubernetes sbom spdx
Last synced: 07 Aug 2025
https://github.com/CycloneDX/cyclonedx-cli
CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.
bill-of-materials bom cyclonedx hacktoberfest mbom obom owasp package-url purl saasbom sbom sbom-generator software-bill-of-materials spdx vex
Last synced: 14 Apr 2025
https://github.com/cyclonedx/cyclonedx-cli
CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.
bill-of-materials bom cyclonedx hacktoberfest mbom obom owasp package-url purl saasbom sbom sbom-generator software-bill-of-materials spdx vex
Last synced: 08 Apr 2025
https://github.com/cyclonedx/cyclonedx-maven-plugin
Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects
bill-of-materials bom cyclonedx maven maven-plugin mbom obom owasp package-url purl saasbom sbom sbom-generator software-bill-of-materials spdx vex
Last synced: 15 May 2025
https://github.com/spdx/spdx-spec
The System Package Data Exchange (SPDX) specification in Markdown and HTML formats.
bill-of-materials licenses linux-foundation sbom software-bill-of-materials software-package-data-exchange software-transparency spdx spdx-sbom specification
Last synced: 24 Jan 2026
https://github.com/CycloneDX/cyclonedx-maven-plugin
Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects
bill-of-materials bom cyclonedx maven maven-plugin mbom obom owasp package-url purl saasbom sbom sbom-generator software-bill-of-materials spdx vex
Last synced: 08 May 2025
https://github.com/cyclonedx/cyclonedx-python
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
bill-of-materials bom conda cyclonedx environment hacktoberfest owasp package-url pip poetry purl python python3 requirements sbom sbom-generator sbom-tool software-bill-of-materials spdx
Last synced: 16 May 2025
https://github.com/cyclonedx/cyclonedx-dotnet
Creates CycloneDX Software Bill of Materials (SBOM) from .NET Projects
bill-of-materials bom cyclonedx dotnet dotnet-core hacktoberfest mbom obom owasp package-url purl saasbom sbom sbom-generator software-bill-of-materials spdx vex
Last synced: 27 Apr 2026
https://github.com/aboutcode-org/aboutcode
AboutCode project: tools and data to uncover things about code: the provenance, origin, license, and more (packages, security, quality, etc.) of FOSS code. Get started at https://aboutcode.readthedocs.io/
aboutcode dejacode license purl sbom sca scancode security
Last synced: 28 Jan 2026
https://github.com/interlynk-io/sbomqs
sbomqs: The Comprehensive SBOM Quality & Compliance Tool
cyclonedx devsecops-pipeline go golang sbom sbom-examples sbom-quality sbom-samples sbom-score sbom-tool security-tools spdx supply-chain-security
Last synced: 09 Feb 2026
https://github.com/laoshanxi/app-mesh
A secure, high-performance, multi-tenant micro-service platform for remote "App Management" and "Computing"
2fa alertmanager consul-client cron docker grafana-datasource hmac-sha256 in-memory-computing jwt kubernetes loki ninja oauth2 prometheus-exporter psk2 sbom service-mesh websocket
Last synced: 08 Apr 2026
https://github.com/cyclonedx/bom-examples
A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)
bill-of-materials bom cyclonedx mbom obom owasp saasbom sbom sbom-examples software-bill-of-materials vex
Last synced: 12 Feb 2026
https://github.com/ckotzbauer/sbom-operator
Catalogue all images of a Kubernetes cluster to multiple targets with Syft
k8s kubernetes operator sbom supply-chain-security
Last synced: 09 Apr 2025
https://github.com/cyclonedx/cyclonedx-gradle-plugin
Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects
bill-of-materials bom cyclonedx gradle gradle-plugin owasp package-url purl sbom sbom-generator software-bill-of-materials spdx
Last synced: 13 Feb 2026
https://github.com/CycloneDX/bom-examples
A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)
bill-of-materials bom cyclonedx mbom obom owasp saasbom sbom sbom-examples software-bill-of-materials vex
Last synced: 08 May 2025
https://github.com/snyk/parlay
Enrich SBOMs with data from third party services
Last synced: 03 Apr 2025
https://github.com/tiiuae/sbomnix
A suite of utilities to help with software supply chain challenges on nix targets
bill-of-materials cpe cyclonedx dependencies nix purl python sbom sbom-generator sbom-tool security software-bill-of-materials software-supply-chain software-supply-chain-security spdx-sbom static-analysis vulnerability-scanners
Last synced: 04 Apr 2025
https://github.com/cyclonedx/cyclonedx-gomod
Creates CycloneDX Software Bill of Materials (SBOM) from Go modules
bill-of-materials bom go-modules golang mbom obom owasp saasbom sbom sbom-generator software-bill-of-materials vex
Last synced: 16 May 2025
https://github.com/anchore/grant
A license scanner for container images and filesystems.
compliance golang license sbom static-analysis
Last synced: 18 Feb 2026
https://github.com/oracle/macaron
Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks, detect malicious Python packages, or check conformance to frameworks, such as SLSA. Documentation:
build-system cicd docker gradle integrity-protection malware-analysis malware-detection maven npm python sbom slsa supply-chain-security
Last synced: 25 Feb 2026
https://github.com/trailofbits/deptective
Deptective automatically determines the native dependencies required to run any arbitrary program or command.
dependency-analysis sbom sbom-tool
Last synced: 27 Jun 2026
https://github.com/cyclonedx/cyclonedx-rust-cargo
Creates CycloneDX Software Bill of Materials (SBOM) from Rust (Cargo) projects
bill-of-materials bom cargo cargo-plugin cyclonedx mbom obom owasp package-url purl rust saasbom sbom sbom-generator software-bill-of-materials spdx vex
Last synced: 15 May 2025
https://github.com/cyclonedx/cyclonedx-node-module
creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects
bom cyclonedx dependency-graph meta-package metapackage node nodejs sbom sbom-generator sbom-tool software-bill-of-materials
Last synced: 15 May 2025
https://github.com/fatihtokus/scan2html
A Trivy plugin that scans and outputs the results (vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more) to an interactive html file.
cisa cisa-kev cloud containers devops devsecops epss iac misconfiguration opensource report sbom scan secops security trivy vulnerability vulnerability-management
Last synced: 09 Mar 2026
https://github.com/cyclonedx/sbom-utility
Utility that provides an API platform for validating, querying and managing BOM data
bill-of-materials bom cyclonedx hacktoberfest mbom obom owasp package-url purl saasbom sbom sbom-quality sbom-tool software-bill-of-materials spdx spdx-license spdx-sbom vdr vex
Last synced: 23 Oct 2025
https://github.com/mchmarny/s3cme
Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance
attestation cosine oidc provenance sbom slsa supply-chain-security vulnerability
Last synced: 23 Jun 2025
https://github.com/OWASP/KubeLight
OWASP Kubernetes security and compliance tool [WIP]
cis compliance containers cve-scanning devsecops docker kubernetes kubernetes-security nsa owasp pci-dss python sbom scanner security security-tools vulnerability-management
Last synced: 10 May 2025
https://github.com/spdx/spdx-3-model
The model for the information captured in SPDX version 3 standard.
bill-of-materials linux-foundation ontology sbom software-bill-of-materials software-package-data-exchange software-transparency spdx spdx-sbom
Last synced: 15 Feb 2026
https://github.com/cyclonedx/cyclonedx-core-java
CycloneDX SBOM Model and Utils for Creating and Validating BOMs
bill-of-materials bom cyclonedx library mbom obom owasp package-url purl saasbom sbom software-bill-of-materials spdx vex
Last synced: 14 May 2025
https://github.com/openclarity/vmclarity
VMClarity is a tool for agentless detection and management of Virtual Machine Software Bill Of Materials (SBOM) and vulnerabilities
agentless cloud exploits leaked-secrets malware misconfigurations rootkits sbom secrets-detection security vulnerabilities vulnerability-scanners
Last synced: 06 Apr 2025
https://github.com/relizaio/rearm
ReARM - Release-Level Supply Chain Evidence Platform. SBOMs, xBOMs and every other artifact - stored for 10+ years, versioned and audit-ready.
cyclonedx cyclonedx-sbom hardware-supplychain release release-automation release-engineering release-management sbom sbom-distribution sbom-tool security security-tools software-supply-chain software-supply-chain-security software-transparency supply-chain supply-chain-management supply-chain-visibility vulnerability
Last synced: 25 Feb 2026
https://github.com/cyclonedx/cyclonedx-node-npm
Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.
bill-of-materials bom cyclonedx dependency-graph hacktoberfest node nodejs npm owasp sbom sbom-generator sbom-tool software-bill-of-materials
Last synced: 15 May 2025
https://github.com/cyclonedx/cyclonedx-go
Go library to consume and produce CycloneDX Software Bill of Materials (SBOM)
bill-of-materials bom golang library mbom obom owasp saasbom sbom software-bill-of-materials vex
Last synced: 15 May 2025
https://github.com/Trusera/ai-bom
AI Bill of Materials — discover every AI agent, model, and API in your infrastructure
ai ai-security bill-of-materials cyclonedx github-actions llm sarif sbom security
Last synced: 24 Feb 2026
https://github.com/spdx/ntia-conformance-checker
Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.
compliance ntia sbom sbom-tool software-bill-of-materials spdx
Last synced: 17 Mar 2026
https://github.com/inno-devops-labs/devsecops-intro
🚀 DevSecOps intro elective — 10 hands-on labs + 2 bonus hardening OWASP Juice Shop: threat modeling (STRIDE/Threagile), signed commits & secret scanning, SBOM/SCA, SAST + DAST, IaC security (Checkov/KICS), container & supply-chain hardening (Trivy, Cosign), runtime detection with Falco, and DefectDojo vuln management.
container-security cosign course dast defectdojo devsecops education falco hands-on-labs iac-security juice-shop sast sbom security supply-chain-security threat-modeling trivy
Last synced: 22 Aug 2026
https://github.com/ckotzbauer/vulnerability-operator
Scans SBOMs for vulnerabilities with Grype
cve grype kubernetes policyreport sbom security vulnerabilities
Last synced: 06 Apr 2025
https://github.com/cyclonedx/cyclonedx-python-lib
Python implementation of OWASP CycloneDX
attestation bill-of-materials bom cbom cyclonedx hacktoberfest library mbom obom owasp package-url purl python saasbom sbom software-bill-of-materials software-library spdx vex
Last synced: 15 May 2025
https://github.com/nikstur/bombon
Nix CycloneDX Software Bills of Materials (SBOMs)
bill-of-materials bom components cyclonedx dependencies license nix nixos purl sbom sbom-generator software-bill-of-materials spdx
Last synced: 07 Apr 2025
https://github.com/oxsecurity/codetotal
Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security, vulnerability, insecure infrastructure as code, and potential legal issues with open source licenses.
code-quality-analyzer iac megalinter sast sbom sbom-generator secrets-detection security supply-chain supply-chain-security vulnerability-scanners
Last synced: 06 Aug 2025
https://github.com/cyclonedx/transparency-exchange-api
A standard API specification for exchanging supply chain artifacts and intelligence
api-spec bill-of-materials bom cyclonedx owasp sbom sbom-distribution software-bill-of-materials specification tc54
Last synced: 07 Apr 2025
https://github.com/trailofbits/vendetect
A tool to automatically detect copy+pasted and vendored code between repositories
plagiarism-detection program-analysis sbom sbom-tool
Last synced: 14 Dec 2025
https://github.com/kubernetes-sigs/tejolote
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
attestation provenance sbom sigstore slsa
Last synced: 06 Apr 2026
https://github.com/cyclonedx/cyclonedx-bom-repo-server
A BOM repository server for distributing CycloneDX BOMs
bill-of-materials bom cyclonedx mbom obom owasp saasbom sbom sbom-distribution sbom-repository software-bill-of-materials vex
Last synced: 15 Apr 2025
https://github.com/CycloneDX/cyclonedx-python-lib
Python implementation of OWASP CycloneDX
attestation bill-of-materials bom cbom cyclonedx hacktoberfest library mbom obom owasp package-url purl python saasbom sbom software-bill-of-materials software-library spdx vex
Last synced: 07 May 2025
https://github.com/bgeesaman/malicious-compliance
Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"
Last synced: 11 Apr 2025
https://github.com/CycloneDX/cyclonedx-php-composer
Create CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects
bill-of-materials bom composer composer-plugin cyclonedx dependency-graph hacktoberfest owasp package-url php purl sbom sbom-generator sbom-tool software-bill-of-materials spdx
Last synced: 13 May 2025
https://github.com/edoardottt/depsdev
CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.
blue-team cargo defensive-security dependency-management dependency-scanning dependency-security go go-module golang-module hacktoberfest maven npm nuget package-security pypi sbom sbom-generator security supply-chain supply-chain-management
Last synced: 14 Apr 2026
https://github.com/patriksvensson/covenant
A tool to generate SBOM (Software Bill of Material) from source code artifacts.
Last synced: 15 Apr 2025
https://github.com/gitsocial-org/gitsocial
Git-native cross-forge collaboration platform
bubbletea cli cross-forge decentralized git go kanban rpc sbom scrum social tui
Last synced: 19 May 2026
https://github.com/scanoss/sbom-workbench
The SCANOSS SBOM Workbench graphical user interface to scan and audit your source code.
license open-source sbom sbom-generator software-composition-analysis
Last synced: 04 Mar 2026
https://github.com/cyclonedx/cyclonedx-php-composer
Create CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects
bill-of-materials bom composer composer-plugin cyclonedx dependency-graph hacktoberfest owasp package-url php purl sbom sbom-generator sbom-tool software-bill-of-materials spdx
Last synced: 31 Mar 2025
https://github.com/goreleaser/example-supply-chain
Example goreleaser + github actions config with keyless signing and SBOM generation
cosign go golang goreleaser sbom signing sigstore software-bill-of-materials supply-chain syft
Last synced: 19 Apr 2026
https://github.com/cbomkit/sonar-cryptography
This repository contains a SonarQube Plugin that detects cryptographic assets in source code and generates CBOM.
cbom cbom-tool cbomkit crypto-scanner cryptographic-inventory cryptography cryptography-bom post-quantum post-quantum-cryptography quantum-safe sbom sbom-tool sonar sonarqube
Last synced: 04 Feb 2026
https://github.com/tweag/genealogos
Genealogos, a Nix sbom generator
cyclonedx nix sbom sbom-generator
Last synced: 03 Feb 2026
https://github.com/jenkinsci/dependency-track-plugin
Main repository for the official Dependency-Track Jenkins plugin
appsec bom builder component-analysis jenkins jenkins-pipeline jenkins-plugin owasp report sbom security
Last synced: 08 Apr 2025