Todas las etiquetas
Etiqueta del catálogo

#sbom

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

38 registros
Con la etiqueta «sbom»Ordenado por índice de salud
Go
85Excelenteíndice de salud
anchore/syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
Go★ 926221 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
Go
85Excelenteíndice de salud
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
Go · npm
83Buenoíndice de salud
zarf-dev/zarf
The Airgap Native Package Manager for Kubernetes
Go★ 198522 jul 2026
Apache-2.022 jul 2026 · métricas 1.13.0
PyPI · npm
80Buenoíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
Maven · npm
80Buenoíndice de salud
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Kotlin★ 205117 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
77Buenoíndice de salud
microsoft/component-detection
Scans your project to determine what components you use
C#★ 54518 jul 2026
MIT18 jul 2026 · métricas 1.13.0
PyPI
76Buenoíndice de salud
CycloneDX/cyclonedx-python-lib
Functionality and DataModels of OWASP CycloneDX for Python
Python★ 11317 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
npm · Maven · NuGet +1
76Buenoíndice de salud
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1012↓ 719.2K/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
npm
76Buenoíndice de salud
janbiasi/rollup-plugin-sbom
Create SBOMs in CycloneDX format for your Vite, Rollup or Rolldown projects with ease
TypeScript★ 23↓ 177.5K/mes17 jul 2026
MIT17 jul 2026 · métricas 1.13.0
PyPI
75Buenoíndice de salud
fsfe/reuse-tool
This is a mirror of https://codeberg.org/fsfe/reuse-tool
Python★ 583↓ 552.1K/mes21 jul 2026
Licencia propia21 jul 2026 · métricas 1.13.0
PyPI
75Buenoíndice de salud
kdeldycke/meta-package-manager
🎁 wraps all package managers with a unifying CLI
Python★ 60920 jul 2026
GPL-2.020 jul 2026 · métricas 1.13.0
PyPI · npm
74Buenoíndice de salud
NuGuardAI/nuguard
opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
Python★ 10↓ 4954/mes18 jul 2026
Licencia propia18 jul 2026 · métricas 1.13.0
npm
72Buenoíndice de salud
cyclonedx/cyclonedx-node-module
creates CycloneDX Software-Bill-of-Materials (SBOM) from Node.js-based projects
Mixto★ 143↓ 84.4K/mes14 jul 2026
Apache-2.014 jul 2026 · métricas 1.13.0
Maven · npm
72Buenoíndice de salud
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 6615 jul 2026
Apache-2.015 jul 2026 · métricas 1.13.0
PyPI
71Buenoíndice de salud
aboutcode-org/scancode-toolkit
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!
Python · C · Shell★ 258321 jul 2026
Licencia propia21 jul 2026 · métricas 1.13.0
npm
71Buenoíndice de salud
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2247/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0
Go · PyPI
71Buenoíndice de salud
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Hex
71Buenoíndice de salud
erlef/mix_sbom
Mix task to generate a Software Bill-of-Materials (SBoM) in CycloneDX format
Elixir★ 47↓ 29.6K/mes17 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
PyPI · npm
71Buenoíndice de salud
lgtm-hq/py-lintro
Making linters play nice... Mostly.
Python★ 1↓ 8269/mes17 jul 2026
MIT17 jul 2026 · métricas 1.13.0
NuGet
70Buenoíndice de salud
CycloneDX/cyclonedx-dotnet-library
.NET library to consume and produce CycloneDX Software Bill of Materials (SBOM)
C#★ 2822 jul 2026
Apache-2.022 jul 2026 · métricas 1.13.0
70Buenoíndice de salud
microsoft/sbom-tool
The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.
C#★ 204717 jul 2026
MIT17 jul 2026 · métricas 1.13.0
crates.io
69Moderadoíndice de salud
guacsec/trustify
SBOM analysis platform for storing, correlating, and querying software bill of materials and security advisories (CSAF/VEX, OSV, CVE) at scale.
Rust★ 6117 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
NuGet
69Moderadoíndice de salud
package-url/packageurl-dotnet
.NET parser for Package URLs (ECMA-427)
C#★ 1718 jul 2026
MIT18 jul 2026 · métricas 1.13.0
PyPI
68Moderadoíndice de salud
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1928/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
68Moderadoíndice de salud
voltone/rebar3_sbom
Rebar3 plugin to generate CycloneDX SBoM
Erlang★ 1217 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
Go
67Moderadoíndice de salud
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 2420 jul 2026
Apache-2.020 jul 2026 · métricas 1.13.0
PyPI
67Moderadoíndice de salud
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/mes14 jul 2026
Licencia propia14 jul 2026 · métricas 1.13.0
Go
66Moderadoíndice de salud
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 821 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
Go
64Moderadoíndice de salud
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 221 jul 2026
BSD-3-Clause21 jul 2026 · métricas 1.13.0
Go
61Moderadoíndice de salud
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 119 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0