Todas las etiquetas
Etiqueta del catálogo

#sca

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

21 registros
Con la etiqueta «sca»Ordenado por índice de salud
Maven · npm
94Excepcionalíndice de salud
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Kotlin★ 205117 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
PyPI
93Excepcionalíndice de salud
SocketDev/socket-python-cli
Socket Python CLI to use in integrations
Python★ 9↓ 183.3K/mes21 jul 2026
MIT21 jul 2026 · métricas 2.10.0
npm · Maven · NuGet +1
92Excelenteíndice de salud
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1018↓ 745.3K/mes28 jul 2026
Apache-2.028 jul 2026 · métricas 2.10.0
PyPI
90Excelenteíndice de salud
CycloneDX/cyclonedx-python-lib
Functionality and DataModels of OWASP CycloneDX for Python
Python★ 11317 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
RubyGems
89Excelenteíndice de salud
pay-rails/pay
Payments for Ruby on Rails apps
Ruby★ 224930 jul 2026
MIT30 jul 2026 · métricas 2.10.0
PyPI
88Excelenteíndice de salud
cycodehq/cycode-cli
Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning
Python★ 99↓ 127.9K/mes27 jul 2026
MIT27 jul 2026 · métricas 2.10.0
PyPI
86Excelenteíndice de salud
aboutcode-org/scancode-toolkit
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!
Python · C · Shell★ 258321 jul 2026
Licencia propia21 jul 2026 · métricas 2.10.0
Go · PyPI
86Excelenteíndice de salud
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
Maven · npm
86Excelenteíndice de salud
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 6615 jul 2026
Apache-2.015 jul 2026 · métricas 2.10.0
PyPI · npm
84Excelenteíndice de salud
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1281↓ 10.9K/mes24 ago 2026
MIT24 ago 2026 · métricas 2.10.0
Packagist
81Excelenteíndice de salud
Sylius/StripePlugin
Sylius ^2.0 plugin to support Stripe Checkout and Stripe Web Elements
PHP★ 12↓ 17.5K/mes5 sept 2026
MIT5 sept 2026 · métricas 2.10.0
NuGet
81Excelenteíndice de salud
package-url/packageurl-dotnet
.NET parser for Package URLs (ECMA-427)
C#★ 1718 jul 2026
MIT18 jul 2026 · métricas 2.10.0
Packagist
80Excelenteíndice de salud
Sylius/PayumStripePlugin
Sylius Payum Stripe gateway plugin (with SCA support)
PHP · Gherkin★ 61↓ 2134/mes5 sept 2026
MIT5 sept 2026 · métricas 2.10.0
Go
77Buenoíndice de salud
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go · npm · PyPI
75Buenoíndice de salud
KKloudTarus/synapse-ce
Synapse - a governed control plane for software composition analysis, recon, evidence, and reporting. Verify Everything. Trust Nothing.
Go · Python★ 336 ago 2026
Apache-2.06 ago 2026 · métricas 2.10.0
Go
71Buenoíndice de salud
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 255 sept 2026
Licencia propia5 sept 2026 · métricas 2.10.0
npm
69Buenoíndice de salud
patchstack/connect
Patchstack connector for JavaScript applications. Scans your lockfile and reports installed packages to Patchstack for vulnerability monitoring.
TypeScript · JavaScript★ 1↓ 4203/mes20 jul 2026
MIT20 jul 2026 · métricas 2.10.0
63Moderadoíndice de salud
tonycknight/pkgchk-cli
A dotnet tool for package dependency checks.
F#★ 31 ago 2026
MIT1 ago 2026 · métricas 2.10.0
Go · npm
62Moderadoíndice de salud
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 319 jul 2026
MIT19 jul 2026 · métricas 2.10.0
npm
14Críticoíndice de salud
CycloneDX/cdxgen-action
GitHub action for CycloneDX BOM generator (cdxgen). cdxgen produced bom xml file can be uploaded to dependency track, AppThreat and other commercial Software Composition Analysis (SCA) products
JavaScript★ 1122 jul 2026
MIT22 jul 2026 · métricas 2.10.0