15 skills found
chainloop-dev / ChainloopSDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
bomctl / BomctlFormat agnostic SBOM tooling
relizaio / RearmReARM - Release-Level Supply Chain Evidence Platform. SBOMs, xBOMs and every other artifact - stored for 10+ years, versioned and audit-ready.
CycloneDX / Transparency Exchange ApiA standard API specification for exchanging supply chain artifacts and intelligence
CycloneDX / Cyclonedx Bom Repo ServerA BOM repository server for distributing CycloneDX BOMs
CycloneDX / Cyclonedx Linux GeneratorLockheed Martin developed utility to generate CycloneDX SBOMs for Linux distributions
siemens / DebsbomSBOM generator for Debian-based distributions
SecureStackCo / Actions SbomA GitHub Action that creates a SBOM from your application so you can meet compliance and security requirements. Add this to your dev, staging and prod steps and SecureStack will make sure that what you've just deployed is secure and meets your requirements, and has the SBOM to show it!
interlynk-io / SbomexSBOM Explorer - Discover and pull public SBOMs
MedUnes / Dtrack CliA Go-based CLI tool to automate the upload and lifecycle management of Software Bill of Materials (SBOM) in OWASP Dependency-Track.
whimsicalevoc / SbomexSBOM Explorer - Discover and pull public SBOMs sbom, sbom-distribution, sbom-examples, sbom-repository, sbom-samples, sbom-tool
sethmlarson / Pip SbomGenerate Software Bill-of-Materials (SBOMs) for Python environments from distribution metadata
relizaio / Rearm CliCLI to interact with ReARM SBOM / xBOM and Release Manager
codenotary / Sbom.sh ContainerDockerfile and scripts to build a container image that facilitates generating and uploading Software Bill of Materials (SBOM) to sbom.sh utilizing various open-source SBOM tools such as Trivy, Grype, and Syft.
PatrickStarBaby / LiPSBOMakerLiPSBOMaker is an SBOM generation tool for Linux distributions. It is a command-line tool that can generate multi-stage SBOMs for Linux packages, including the source stage, release stage, and runtime stage.