Showing 1-8 of 8 projects
A CLI tool and library for generating SBOMs (Software Bill of Materials) from container images and filesystems.
Detects licenses, copyrights, and dependencies in code to help developers discover open-source packages.
A highly scalable and enterprise-ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.
A suite of tools to automate software compliance checks for open-source projects.
GUAC aggregates software security metadata into a high fidelity graph database.
Tools for working with the SPDX license list and validating licenses.
An open-source software supply chain security solution for detecting dependencies, vulnerabilities, and license compliance.
Tern is a software composition analysis tool that generates a Software Bill of Materials for container images and Dockerfiles.
Get weekly updates on trending AI coding tools and projects.