Todas las etiquetas
Etiqueta del catálogo

#sbom

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

61 registros
Con la etiqueta «sbom»Ordenado por índice de salud
Go
98Excepcionalíndice de salud
anchore/syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
Go★ 946528 ago 2026
Apache-2.028 ago 2026 · métricas 2.10.0
Go
98Excepcionalíndice de salud
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
Go · npm
97Excepcionalíndice de salud
zarf-dev/zarf
The Airgap Native Package Manager for Kubernetes
Go★ 198522 jul 2026
Apache-2.022 jul 2026 · métricas 2.10.0
PyPI
95Excepcionalíndice de salud
CycloneDX/cyclonedx-python
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
Python★ 390↓ 2.2M/mes27 ago 2026
Apache-2.027 ago 2026 · métricas 2.10.0
Go
94Excepcionalíndice de salud
kubernetes-sigs/tejolote
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Go★ 7324 jul 2026
Apache-2.024 jul 2026 · métricas 2.10.0
PyPI · npm
94Excepcionalíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
Maven · npm
94Excepcionalíndice de salud
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Kotlin★ 205117 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
npm · Maven · NuGet +1
92Excelenteíndice de salud
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1018↓ 745.3K/mes28 jul 2026
Apache-2.028 jul 2026 · métricas 2.10.0
92Excelenteíndice de salud
microsoft/component-detection
Scans your project to determine what components you use
C#★ 54518 jul 2026
MIT18 jul 2026 · métricas 2.10.0
Packagist
91Excelenteíndice de salud
CycloneDX/cyclonedx-php-composer
Create CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects
PHP★ 87↓ 91.9K/mes29 jul 2026
Apache-2.029 jul 2026 · métricas 2.10.0
PyPI
90Excelenteíndice de salud
CycloneDX/cyclonedx-python-lib
Functionality and DataModels of OWASP CycloneDX for Python
Python★ 11317 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
PyPI · npm
89Excelenteíndice de salud
NuGuardAI/nuguard
opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
Python★ 10↓ 4954/mes18 jul 2026
Licencia propia18 jul 2026 · métricas 2.10.0
PyPI
89Excelenteíndice de salud
fsfe/reuse-tool
This is a mirror of https://codeberg.org/fsfe/reuse-tool
Python★ 583↓ 552.1K/mes21 jul 2026
Licencia propia21 jul 2026 · métricas 2.10.0
npm
89Excelenteíndice de salud
janbiasi/rollup-plugin-sbom
Create SBOMs in CycloneDX format for your Vite, Rollup or Rolldown projects with ease
TypeScript★ 23↓ 177.5K/mes17 jul 2026
MIT17 jul 2026 · métricas 2.10.0
PyPI
89Excelenteíndice de salud
kdeldycke/meta-package-manager
🎁 wraps all package managers with a unifying CLI
Python★ 60920 jul 2026
GPL-2.020 jul 2026 · métricas 2.10.0
Go · npm
89Excelenteíndice de salud
seebom-labs/BOMHort
About standalone, Kubernetes-native Software Bill of Materials (SBOM) visualization and governance platform
Go · TypeScript★ 2829 jul 2026
Apache-2.029 jul 2026 · métricas 2.10.0
npm
88Excelenteíndice de salud
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5893/mes6 sept 2026
MIT6 sept 2026 · métricas 2.10.0
PyPI
88Excelenteíndice de salud
jimmy058910/jmo-security-repo
JMo Security Suite - Terminal-first security audit toolkit with many tools, multi-target scanning, & compliance
Python★ 731 jul 2026
Licencia propia31 jul 2026 · métricas 2.10.0
Go
86Excelenteíndice de salud
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 024 jul 2026
Apache-2.024 jul 2026 · métricas 2.10.0
PyPI
86Excelenteíndice de salud
aboutcode-org/scancode-toolkit
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!
Python · C · Shell★ 258321 jul 2026
Licencia propia21 jul 2026 · métricas 2.10.0
Go · PyPI
86Excelenteíndice de salud
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
Maven · npm
86Excelenteíndice de salud
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 6615 jul 2026
Apache-2.015 jul 2026 · métricas 2.10.0
crates.io
86Excelenteíndice de salud
rust-secure-code/cargo-auditable
Make production Rust binaries auditable
Rust★ 849↓ 3M/mes5 sept 2026
Apache-2.05 sept 2026 · métricas 2.10.0
npm
84Excelenteíndice de salud
CycloneDX/cyclonedx-node-module
creates CycloneDX Software-Bill-of-Materials (SBOM) from Node.js-based projects
Mixto★ 145↓ 76.5K/mes5 sept 2026
Apache-2.05 sept 2026 · métricas 2.10.0
PyPI · npm
84Excelenteíndice de salud
lgtm-hq/py-lintro
Making linters play nice... Mostly.
Python★ 1↓ 8269/mes17 jul 2026
MIT17 jul 2026 · métricas 2.10.0
PyPI · npm
84Excelenteíndice de salud
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1281↓ 10.9K/mes24 ago 2026
MIT24 ago 2026 · métricas 2.10.0
PyPI
84Excelenteíndice de salud
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 5022 ago 2026
Licencia propia22 ago 2026 · métricas 2.10.0
Go · npm
83Excelenteíndice de salud
CodesWhat/portwing
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 415 ago 2026
AGPL-3.015 ago 2026 · métricas 2.10.0
83Excelenteíndice de salud
CycloneDX/cyclonedx-cli
CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.
C#★ 53321 ago 2026
Apache-2.021 ago 2026 · métricas 2.10.0
NuGet
83Excelenteíndice de salud
CycloneDX/cyclonedx-dotnet-library
.NET library to consume and produce CycloneDX Software Bill of Materials (SBOM)
C#★ 2822 jul 2026
Apache-2.022 jul 2026 · métricas 2.10.0