All tags
Catalogue tag

#sbom

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

61 records
Tagged “sbom”Ranked by health index
Go
98Exceptionalhealth index
anchore/syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
Go★ 9,465Aug 28, 2026
Apache-2.0Aug 28, 2026 · metrics 2.10.0
Go
98Exceptionalhealth index
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 570Jul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 2.10.0
Go · npm
97Exceptionalhealth index
zarf-dev/zarf
The Airgap Native Package Manager for Kubernetes
Go★ 1,985Jul 22, 2026
Apache-2.0Jul 22, 2026 · metrics 2.10.0
PyPI
95Exceptionalhealth index
CycloneDX/cyclonedx-python
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
Python★ 390↓ 2.2M/moAug 27, 2026
Apache-2.0Aug 27, 2026 · metrics 2.10.0
Go
94Exceptionalhealth index
kubernetes-sigs/tejolote
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Go★ 73Jul 24, 2026
Apache-2.0Jul 24, 2026 · metrics 2.10.0
PyPI · npm
94Exceptionalhealth index
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 2.10.0
Maven · npm
94Exceptionalhealth index
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Kotlin★ 2,051Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
npm · Maven · NuGet +1
92Excellenthealth index
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1,018↓ 745.3K/moJul 28, 2026
Apache-2.0Jul 28, 2026 · metrics 2.10.0
92Excellenthealth index
microsoft/component-detection
Scans your project to determine what components you use
C#★ 545Jul 18, 2026
MITJul 18, 2026 · metrics 2.10.0
Packagist
91Excellenthealth index
CycloneDX/cyclonedx-php-composer
Create CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects
PHP★ 87↓ 91.9K/moJul 29, 2026
Apache-2.0Jul 29, 2026 · metrics 2.10.0
PyPI
90Excellenthealth index
CycloneDX/cyclonedx-python-lib
Functionality and DataModels of OWASP CycloneDX for Python
Python★ 113Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
PyPI · npm
89Excellenthealth index
NuGuardAI/nuguard
opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
Python★ 10↓ 4,954/moJul 18, 2026
Custom licenseJul 18, 2026 · metrics 2.10.0
PyPI
89Excellenthealth index
fsfe/reuse-tool
This is a mirror of https://codeberg.org/fsfe/reuse-tool
Python★ 583↓ 552.1K/moJul 21, 2026
Custom licenseJul 21, 2026 · metrics 2.10.0
npm
89Excellenthealth index
janbiasi/rollup-plugin-sbom
Create SBOMs in CycloneDX format for your Vite, Rollup or Rolldown projects with ease
TypeScript★ 23↓ 177.5K/moJul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
PyPI
89Excellenthealth index
kdeldycke/meta-package-manager
🎁 wraps all package managers with a unifying CLI
Python★ 609Jul 20, 2026
GPL-2.0Jul 20, 2026 · metrics 2.10.0
Go · npm
89Excellenthealth index
seebom-labs/BOMHort
About standalone, Kubernetes-native Software Bill of Materials (SBOM) visualization and governance platform
Go · TypeScript★ 28Jul 29, 2026
Apache-2.0Jul 29, 2026 · metrics 2.10.0
npm
88Excellenthealth index
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/moSep 6, 2026
MITSep 6, 2026 · metrics 2.10.0
PyPI
88Excellenthealth index
jimmy058910/jmo-security-repo
JMo Security Suite - Terminal-first security audit toolkit with many tools, multi-target scanning, & compliance
Python★ 7Jul 31, 2026
Custom licenseJul 31, 2026 · metrics 2.10.0
Go
86Excellenthealth index
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 0Jul 24, 2026
Apache-2.0Jul 24, 2026 · metrics 2.10.0
PyPI
86Excellenthealth index
aboutcode-org/scancode-toolkit
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!
Python · C · Shell★ 2,583Jul 21, 2026
Custom licenseJul 21, 2026 · metrics 2.10.0
Go · PyPI
86Excellenthealth index
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 9Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
Maven · npm
86Excellenthealth index
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 66Jul 15, 2026
Apache-2.0Jul 15, 2026 · metrics 2.10.0
crates.io
86Excellenthealth index
rust-secure-code/cargo-auditable
Make production Rust binaries auditable
Rust★ 849↓ 3M/moSep 5, 2026
Apache-2.0Sep 5, 2026 · metrics 2.10.0
npm
84Excellenthealth index
CycloneDX/cyclonedx-node-module
creates CycloneDX Software-Bill-of-Materials (SBOM) from Node.js-based projects
Mixed★ 145↓ 76.5K/moSep 5, 2026
Apache-2.0Sep 5, 2026 · metrics 2.10.0
PyPI · npm
84Excellenthealth index
lgtm-hq/py-lintro
Making linters play nice... Mostly.
Python★ 1↓ 8,269/moJul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
PyPI · npm
84Excellenthealth index
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1,281↓ 10.9K/moAug 24, 2026
MITAug 24, 2026 · metrics 2.10.0
PyPI
84Excellenthealth index
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 50Aug 22, 2026
Custom licenseAug 22, 2026 · metrics 2.10.0
Go · npm
83Excellenthealth index
CodesWhat/portwing
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 4Aug 15, 2026
AGPL-3.0Aug 15, 2026 · metrics 2.10.0
83Excellenthealth index
CycloneDX/cyclonedx-cli
CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.
C#★ 533Aug 21, 2026
Apache-2.0Aug 21, 2026 · metrics 2.10.0
NuGet
83Excellenthealth index
CycloneDX/cyclonedx-dotnet-library
.NET library to consume and produce CycloneDX Software Bill of Materials (SBOM)
C#★ 28Jul 22, 2026
Apache-2.0Jul 22, 2026 · metrics 2.10.0