Stars
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure
GUAC aggregates software security metadata into a high fidelity graph database.
Build a local copy of CVE (NVD and Japanese JVN). Server mode for easy querying.
OSV-SCALIBR: A library for Software Composition Analysis
A universal SBOM representation in protocol buffers
Generate a score for your sbom to understand if it will actually be useful.
SBOM Assess - Evaluate SBOM quality and compliance
fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool's strength.