GitHub 中文社区
回车: Github搜索    Shift+回车: Google搜索
论坛
排行榜
趋势
登录

©2025 GitHub中文社区论坛GitHub官网网站地图GitHub官方翻译

  • X iconGitHub on X
  • Facebook iconGitHub on Facebook
  • Linkedin iconGitHub on LinkedIn
  • YouTube iconGitHub on YouTube
  • Twitch iconGitHub on Twitch
  • TikTok iconGitHub on TikTok
  • GitHub markGitHub’s organization on GitHub
集合主题趋势排行榜
#

spdx

Website
Wikipedia
anchore/syft
https://static.github-zh.com/github_avatars/anchore?size=40
anchore / syft

syft 是一个 CLI 工具和 Go 库,用于从容器镜像和文件系统生成软件物料清单(SBOM)

containersDockerGostatic-analysis工具ocisbomspdxcyclonedxHacktoberfest
Go 7.2 k
2 天前
https://static.github-zh.com/github_avatars/aboutcode-org?size=40
aboutcode-org / scancode-toolkit

🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nl...

licensecopyrightpackages依赖管理spdxprovenancelicense-scanlicensingspdx-licensesopen-source-licensinglicense-checkingsoftware-composition-analysispurlpackage-urlsbomscacyclonedxdependency-graph
Python 2.3 k
2 天前
oss-review-toolkit/ort
https://static.github-zh.com/github_avatars/oss-review-toolkit?size=40
oss-review-toolkit / ort

A suite of tools to automate software compliance checks.

Package manager依赖管理dependency-graphlicensecopyrightspdxcompliancelicense-managementsbomsbom-generatoropen-source-licensingospocyclonedxscaHacktoberfestcradora
Kotlin 1.76 k
1 天前
https://static.github-zh.com/github_avatars/guacsec?size=40
guacsec / guac

GUAC aggregates software security metadata into a high fidelity graph database.

安全software-supply-chainsoftware-supply-chain-securitysupply-chain-securityattestationsgraphsbomcyclonedxspdxvexvulnerabilityvulnerability-management
Go 1.37 k
4 天前
https://static.github-zh.com/github_avatars/XmirrorSecurity?size=40
XmirrorSecurity / OpenSCA-cli

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the ...

scadevsecops安全sbomsoftware-composition-analysissoftware-supply-chainsoftware-supply-chain-securitystatic-analysisvulnerabilitiescyclonedxspdx
Go 1.08 k
1 个月前
https://static.github-zh.com/github_avatars/tern-tools?size=40
tern-tools / tern

Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-...

PythoncontainerssbomDockercompliancespdx工具依赖管理software-composition-analysisrisk-managementOpen Sourcesupply-chain-security
Python 989
1 年前
https://static.github-zh.com/github_avatars/fossology?size=40
fossology / fossology

FOSSology is an open source license compliance software system and toolkit. As a toolkit you can run license, copyright and export control scans from the command line. As a system, a database and we...

fossologyspdxlicense-managementlicensecomplianceOpen Sourcelicense-checkinglicense-scancompliance-checkcompliance-automationspdx-licenses
HTML 871
4 天前
https://static.github-zh.com/github_avatars/package-url?size=40
package-url / purl-spec

A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby

purlpackage-urlpackageurlcyclonedx依赖管理package-managementsbomspdx
786
5 天前
https://static.github-zh.com/github_avatars/EmbarkStudios?size=40
EmbarkStudios / cargo-about

📜 Cargo plugin to generate list of all licenses for a crate 🦀

cargoRustlicensinglicense-checkingcargo-pluginspdxHacktoberfest
Rust 608
3 个月前
https://static.github-zh.com/github_avatars/devops-kung-fu?size=40
devops-kung-fu / bomber

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

spdxcyclonedxsbomOpen Sourcevulnerability-scannerssyftdevsecopsGo安全security-automation
Go 572
3 个月前
https://static.github-zh.com/github_avatars/spdx?size=40
spdx / license-list-data

Various data formats for the SPDX License List including RDFa, HTML, Text, and JSON

spdxJSONlicensing
HTML 571
5 天前
https://static.github-zh.com/github_avatars/kdeldycke?size=40
kdeldycke / meta-package-manager

🎁 wraps all package managers with a unifying CLI

npmpipHomebrewmacOSmac-app-storeruby-gemLinuxWindowsaptYarnsnapSteamxbarPackage managersbompackage-urlcyclonedxspdx
Python 511
5 天前
https://static.github-zh.com/github_avatars/fsfe?size=40
fsfe / reuse-tool

reuse is a tool for compliance with the REUSE recommendations.

Pythoncopyrightlicensinglinteranalyzerspdxfree-softwaresbom
Python 483
10 天前
https://static.github-zh.com/github_avatars/chainloop-dev?size=40
chainloop-dev / chainloop

Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more

compliancecyclonedxdevsecopssbom安全spdxsupply-chain-securitylicenseopen-source-licensingospoattestation
Go 463
5 天前
https://static.github-zh.com/github_avatars/CycloneDX?size=40
CycloneDX / specification

#计算机科学#OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and V...

bill-of-materialsbom软件spdxlicensesbomcyclonedxowaspstandardspecificationvex机器学习
XSLT 401
4 天前
https://static.github-zh.com/github_avatars/kubernetes-sigs?size=40
kubernetes-sigs / bom

A utility to generate SPDX-compliant Bill of Materials manifests

KubernetesGobomspdxsbom
Go 392
6 天前
https://static.github-zh.com/github_avatars/CycloneDX?size=40
CycloneDX / cyclonedx-cli

CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.

bombill-of-materialspurlpackage-urlsbomcyclonedxspdxowaspsbom-generatorvexHacktoberfest
C# 368
7 个月前
https://static.github-zh.com/github_avatars/spdx?size=40
spdx / spdx-spec

The System Package Data Exchange (SPDX) specification in Markdown and HTML formats.

spdxspecificationbill-of-materialssbom
Python 327
8 天前
https://static.github-zh.com/github_avatars/CycloneDX?size=40
CycloneDX / cyclonedx-maven-plugin

Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects

bomspdxMavenmaven-pluginbill-of-materialspackage-urlpurlsbomcyclonedxowaspsbom-generatorvex
Java 324
1 个月前
https://static.github-zh.com/github_avatars/CycloneDX?size=40
CycloneDX / cyclonedx-python

CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments

Pythonpipbomsbomspdxbill-of-materialspackage-urlpurlcyclonedxowaspsbom-generatorpoetrycondarequirementsenvironmentHacktoberfest
Python 292
3 天前
loading...