GitHub 中文社区
回车: Github搜索    Shift+回车: Google搜索
论坛
排行榜
趋势
登录

©2025 GitHub中文社区论坛GitHub官网网站地图GitHub官方翻译

  • X iconGitHub on X
  • Facebook iconGitHub on Facebook
  • Linkedin iconGitHub on LinkedIn
  • YouTube iconGitHub on YouTube
  • Twitch iconGitHub on Twitch
  • TikTok iconGitHub on TikTok
  • GitHub markGitHub’s organization on GitHub
集合主题趋势排行榜
#

software-composition-analysis

Website
Wikipedia
https://static.github-zh.com/github_avatars/dependency-check?size=40
dependency-check / DependencyCheck

Dependency-Check是一个用于检测应用程序的依赖项(项目中引入的各种库、框架和软件包)中是否存在已知漏洞的工具。 它可以用于各种编程语言和项目类型,包括Java、JavaScript、Python等

安全build-toolmaven-pluginjenkins-plugingradle-pluginvulnerability-detectionant-tasksoftware-composition-analysis
Java 6.98 k
3 天前
https://static.github-zh.com/github_avatars/RetireJS?size=40
RetireJS / retire.js

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

vulnerabilitiesscannerFirefox 插件JavaScriptChrome 插件build-tool安全software-composition-analysissbomsbom-generator
JavaScript 3.86 k
10 天前
DependencyTrack/dependency-track
https://static.github-zh.com/github_avatars/DependencyTrack?size=40
DependencyTrack / dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

owaspappsec安全bomvulnerabilitiescomponent-analysisnvdsoftware-securitysoftware-composition-analysisscabill-of-materialspackage-urlpurlvulnerability-detectionossindexsbomdevsecopssecurity-automationcyclonedxHacktoberfest
Java 3.1 k
1 天前
https://static.github-zh.com/github_avatars/aboutcode-org?size=40
aboutcode-org / scancode-toolkit

🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nl...

licensecopyrightpackages依赖管理spdxprovenancelicense-scanlicensingspdx-licensesopen-source-licensinglicense-checkingsoftware-composition-analysispurlpackage-urlsbomscacyclonedxdependency-graph
Python 2.3 k
2 天前
https://static.github-zh.com/github_avatars/murphysecurity?size=40
murphysecurity / murphysec

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

安全scannerdependencyvulnerability-detectionsoftware-supply-chainscasoftware-composition-analysis
Go 1.73 k
3 天前
https://static.github-zh.com/github_avatars/lunasec-io?size=40
lunasec-io / lunasec

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTra...

tokenizationweb-securitycompliance安全soc2pci-dssgdprzero-trustdevsecopslog4shelldependency-analysisscanningCybersecurityscanning-toolcve-scanningsbomsbom-generatorContinuous Delivery (CD)software-composition-analysis
TypeScript 1.45 k
1 年前
https://static.github-zh.com/github_avatars/XmirrorSecurity?size=40
XmirrorSecurity / OpenSCA-cli

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the ...

scadevsecops安全sbomsoftware-composition-analysissoftware-supply-chainsoftware-supply-chain-securitystatic-analysisvulnerabilitiescyclonedxspdx
Go 1.08 k
1 个月前
https://static.github-zh.com/github_avatars/tern-tools?size=40
tern-tools / tern

Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-...

PythoncontainerssbomDockercompliancespdx工具依赖管理software-composition-analysisrisk-managementOpen Sourcesupply-chain-security
Python 989
1 年前
https://static.github-zh.com/github_avatars/safedep?size=40
safedep / vet

Next Generation Software Composition Analysis (SCA) with Malicious Package Detection, Code Context & Policy as Code

devsecops安全supply-chain-securitypolicy-as-codesoftware-composition-analysisGonpmpypirubygemsstatic-analysisHacktoberfest
Go 494
1 天前
https://static.github-zh.com/github_avatars/microsoft?size=40
microsoft / component-detection

Scans your project to determine what components you use

static-analysis依赖管理package-managementsoftware-composition-analysissbom
C# 485
6 天前
https://static.github-zh.com/github_avatars/bureado?size=40
bureado / awesome-software-supply-chain-security

#Awesome#A compilation of resources in the software supply chain security domain, with emphasis on open source

reproducible-buildssupply-chain-securitydevsecopsvulnerability-scanning安全vulnerability-managementsbompackage-management依赖管理static-analysissoftware-composition-analysissoftware-supply-chainsoftware-supply-chain-securitycve-scanningattestationAwesome Lists
322
2 年前
https://static.github-zh.com/github_avatars/albuch?size=40
albuch / sbt-dependency-check

SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). 🌈

Common Vulnerabilities and Exposures (CVE)Scalavulnerabilitiesnvdappsecsoftware-security安全owaspstatic-analysisvulnerability-scannerssoftware-composition-analysissecurity-automationdevsecopsCybersecurityDevOps
Scala 269
10 个月前
https://static.github-zh.com/github_avatars/stevespringett?size=40
stevespringett / nist-data-mirror

A simple Java command-line utility to mirror the CVE JSON data from NIST.

appsecnvdsoftware-securitynistCommon Vulnerabilities and Exposures (CVE)Javasoftware-composition-analysissca
Java 207
3 年前
https://static.github-zh.com/github_avatars/aboutcode-org?size=40
aboutcode-org / scancode.io

ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabas...

scasoftware-composition-analysisOpen SourcelicenseDockervirtual-machinecyclonedxpackage-urlpurlspdxvulnerabilities
Python 136
2 天前
https://static.github-zh.com/github_avatars/hysnsec?size=40
hysnsec / awesome-sca

A curated list of Software Component Analysis (SCA) books, courses - free and paid, videos, tools, and tutorials.

scacomponent-analysissnykvulnerability-databasessoftware-composition-analysis
105
7 个月前
https://static.github-zh.com/github_avatars/pmckeown?size=40
pmckeown / dependency-track-maven-plugin

Maven plugin that integrates with a Dependency Track server to submit dependency manifests and optionally fail execution when vulnerable dependencies are found.

owaspcomponent-analysissoftware-composition-analysismaven-pluginJavadevsecops
Java 70
13 天前
https://static.github-zh.com/github_avatars/opossum-tool?size=40
opossum-tool / OpossumUI

A light-weight app to audit and inventory large codebases for open source license compliance.

spdxlicense-scansoftware-composition-analysis
TypeScript 65
7 天前
https://static.github-zh.com/github_avatars/nxenon?size=40
nxenon / DevSecOps

♾️ Collection of DevSecOps Notes + Resources + Courses + Tools

devsecopsdevsecops-best-practicesiastsastsbomsecret-managementsecure-codingsoftware-composition-analysisthreat-modeling
Python 64
5 个月前
https://static.github-zh.com/github_avatars/scanoss?size=40
scanoss / sbom-workbench

The SCANOSS SBOM Workbench graphical user interface to scan and audit your source code.

licenseOpen Sourcesbomsbom-generatorsoftware-composition-analysis
TypeScript 53
19 天前
https://static.github-zh.com/github_avatars/ozontech?size=40
ozontech / dtrack-audit

OWASP Dependency Track API client for intergration into CI/CD pipeline

安全component-analysissoftware-composition-analysis
Go 53
1 年前
loading...