GitHub 中文社区
回车: Github搜索    Shift+回车: Google搜索
论坛
排行榜
趋势
登录

©2025 GitHub中文社区论坛GitHub官网网站地图GitHub官方翻译

  • X iconGitHub on X
  • Facebook iconGitHub on Facebook
  • Linkedin iconGitHub on LinkedIn
  • YouTube iconGitHub on YouTube
  • Twitch iconGitHub on Twitch
  • TikTok iconGitHub on TikTok
  • GitHub markGitHub’s organization on GitHub
集合主题趋势排行榜
#

sca

Website
Wikipedia
DependencyTrack/dependency-track
https://static.github-zh.com/github_avatars/DependencyTrack?size=40
DependencyTrack / dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

owaspappsec安全bomvulnerabilitiescomponent-analysisnvdsoftware-securitysoftware-composition-analysisscabill-of-materialspackage-urlpurlvulnerability-detectionossindexsbomdevsecopssecurity-automationcyclonedxHacktoberfest
Java 3.1 k
1 天前
https://static.github-zh.com/github_avatars/aboutcode-org?size=40
aboutcode-org / scancode-toolkit

🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nl...

licensecopyrightpackages依赖管理spdxprovenancelicense-scanlicensingspdx-licensesopen-source-licensinglicense-checkingsoftware-composition-analysispurlpackage-urlsbomscacyclonedxdependency-graph
Python 2.3 k
2 天前
pay-rails/pay
https://static.github-zh.com/github_avatars/pay-rails?size=40
pay-rails / pay

Payments for Ruby on Rails apps

subscriptionstripepayengineRailspayment-providerbraintreescapaddlepaymentsHacktoberfest
Ruby 2.1 k
2 天前
oss-review-toolkit/ort
https://static.github-zh.com/github_avatars/oss-review-toolkit?size=40
oss-review-toolkit / ort

A suite of tools to automate software compliance checks.

Package manager依赖管理dependency-graphlicensecopyrightspdxcompliancelicense-managementsbomsbom-generatoropen-source-licensingospocyclonedxscaHacktoberfestcradora
Kotlin 1.76 k
1 天前
https://static.github-zh.com/github_avatars/murphysecurity?size=40
murphysecurity / murphysec

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

安全scannerdependencyvulnerability-detectionsoftware-supply-chainscasoftware-composition-analysis
Go 1.73 k
4 天前
https://static.github-zh.com/github_avatars/owasp-dep-scan?size=40
owasp-dep-scan / dep-scan

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container ima...

vulnerability-scannersCommon Vulnerabilities and Exposures (CVE)dependency-analysiscontainerssbomscacompliancecyclonedxdevsecops安全vexsupply-chain-security
Python 1.12 k
19 天前
https://static.github-zh.com/github_avatars/XmirrorSecurity?size=40
XmirrorSecurity / OpenSCA-cli

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the ...

scadevsecops安全sbomsoftware-composition-analysissoftware-supply-chainsoftware-supply-chain-securitystatic-analysisvulnerabilitiescyclonedxspdx
Go 1.08 k
1 个月前
https://static.github-zh.com/github_avatars/CycloneDX?size=40
CycloneDX / cdxgen

Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission t...

bomscacyclonedxsbomDockerocicontainersowasppackage-urlpurl
JavaScript 708
3 天前
https://static.github-zh.com/github_avatars/mergebase?size=40
mergebase / log4j-detector

A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instan...

log4jcve-2021-44228cve-2021-45046Cybersecurityscapentestlog4shellscannerdetectorcve-2021-45105vulnerability-scanner
Java 639
3 年前
https://static.github-zh.com/github_avatars/awslabs?size=40
awslabs / automated-security-helper

ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.

Amazon Web ServicesInfrastructure as codesastscascanner安全
Shell 426
5 天前
https://static.github-zh.com/github_avatars/alipay?size=40
alipay / ant-application-security-testing-benchmark

xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".

applicationbenchmarkevaluation安全Testingdastiastsastsca
Java 394
2 个月前
https://static.github-zh.com/github_avatars/Orange-Cyberdefense?size=40
Orange-Cyberdefense / grepmarx

A source code static analysis platform for AppSec enthusiasts.

appsecsastsca安全
Python 251
4 个月前
https://static.github-zh.com/github_avatars/stevespringett?size=40
stevespringett / nist-data-mirror

A simple Java command-line utility to mirror the CVE JSON data from NIST.

appsecnvdsoftware-securitynistCommon Vulnerabilities and Exposures (CVE)Javasoftware-composition-analysissca
Java 207
3 年前
https://static.github-zh.com/github_avatars/aboutcode-org?size=40
aboutcode-org / scancode.io

ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabas...

scasoftware-composition-analysisOpen SourcelicenseDockervirtual-machinecyclonedxpackage-urlpurlspdxvulnerabilities
Python 136
2 天前
https://static.github-zh.com/github_avatars/prancer-io?size=40
prancer-io / cloud-validation-framework

prancer platform is an IaC Security engine + Continuous Compliance for your cloud (Azure, AWS, GCP) and Kubernetes environment

cloudgovernanceInfrastructure as code安全cloudsecuritysca
Python 122
1 年前
https://static.github-zh.com/github_avatars/AppThreat?size=40
AppThreat / vulnerability-db

Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.1, purl, and vers.

vulnerability-detectionCommon Vulnerabilities and Exposures (CVE)nvd命令行界面scaadvisories数据库purl
Python 120
11 天前
https://static.github-zh.com/github_avatars/hysnsec?size=40
hysnsec / awesome-sca

A curated list of Software Component Analysis (SCA) books, courses - free and paid, videos, tools, and tutorials.

scacomponent-analysissnykvulnerability-databasessoftware-composition-analysis
105
7 个月前
https://static.github-zh.com/github_avatars/momosecurity?size=40
momosecurity / mosec-maven-plugin

用于检测maven项目的第三方依赖组件是否存在安全漏洞。

sca依赖管理安全Mavenmaven-plugin
Java 103
3 年前
https://static.github-zh.com/github_avatars/clj-holmes?size=40
clj-holmes / clj-watson

clojure deps SCA

安全Clojurescadependency
Clojure 90
3 个月前
https://static.github-zh.com/github_avatars/cycodehq?size=40
cycodehq / cycode-cli

Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning

Codesastscasecretssecure安全
Python 88
4 天前
loading...