All tags
Catalogue tag

#sbom

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

38 records
Tagged “sbom”Ranked by health index
Go
85Excellenthealth index
anchore/syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
Go★ 9,262Jul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0
Go
85Excellenthealth index
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 570Jul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 1.13.0
Go · npm
83Goodhealth index
zarf-dev/zarf
The Airgap Native Package Manager for Kubernetes
Go★ 1,985Jul 22, 2026
Apache-2.0Jul 22, 2026 · metrics 1.13.0
PyPI · npm
80Goodhealth index
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 1.13.0
Maven · npm
80Goodhealth index
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Kotlin★ 2,051Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
77Goodhealth index
microsoft/component-detection
Scans your project to determine what components you use
C#★ 545Jul 18, 2026
MITJul 18, 2026 · metrics 1.13.0
PyPI
76Goodhealth index
CycloneDX/cyclonedx-python-lib
Functionality and DataModels of OWASP CycloneDX for Python
Python★ 113Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
npm · Maven · NuGet +1
76Goodhealth index
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1,012↓ 719.2K/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
npm
76Goodhealth index
janbiasi/rollup-plugin-sbom
Create SBOMs in CycloneDX format for your Vite, Rollup or Rolldown projects with ease
TypeScript★ 23↓ 177.5K/moJul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
PyPI
75Goodhealth index
fsfe/reuse-tool
This is a mirror of https://codeberg.org/fsfe/reuse-tool
Python★ 583↓ 552.1K/moJul 21, 2026
Custom licenseJul 21, 2026 · metrics 1.13.0
PyPI
75Goodhealth index
kdeldycke/meta-package-manager
🎁 wraps all package managers with a unifying CLI
Python★ 609Jul 20, 2026
GPL-2.0Jul 20, 2026 · metrics 1.13.0
PyPI · npm
74Goodhealth index
NuGuardAI/nuguard
opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
Python★ 10↓ 4,954/moJul 18, 2026
Custom licenseJul 18, 2026 · metrics 1.13.0
npm
72Goodhealth index
cyclonedx/cyclonedx-node-module
creates CycloneDX Software-Bill-of-Materials (SBOM) from Node.js-based projects
Mixed★ 143↓ 84.4K/moJul 14, 2026
Apache-2.0Jul 14, 2026 · metrics 1.13.0
Maven · npm
72Goodhealth index
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 66Jul 15, 2026
Apache-2.0Jul 15, 2026 · metrics 1.13.0
PyPI
71Goodhealth index
aboutcode-org/scancode-toolkit
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!
Python · C · Shell★ 2,583Jul 21, 2026
Custom licenseJul 21, 2026 · metrics 1.13.0
npm
71Goodhealth index
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2,247/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
Go · PyPI
71Goodhealth index
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 9Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
Hex
71Goodhealth index
erlef/mix_sbom
Mix task to generate a Software Bill-of-Materials (SBoM) in CycloneDX format
Elixir★ 47↓ 29.6K/moJul 17, 2026
Custom licenseJul 17, 2026 · metrics 1.13.0
PyPI · npm
71Goodhealth index
lgtm-hq/py-lintro
Making linters play nice... Mostly.
Python★ 1↓ 8,269/moJul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
NuGet
70Goodhealth index
CycloneDX/cyclonedx-dotnet-library
.NET library to consume and produce CycloneDX Software Bill of Materials (SBOM)
C#★ 28Jul 22, 2026
Apache-2.0Jul 22, 2026 · metrics 1.13.0
70Goodhealth index
microsoft/sbom-tool
The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.
C#★ 2,047Jul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
crates.io
69Moderatehealth index
guacsec/trustify
SBOM analysis platform for storing, correlating, and querying software bill of materials and security advisories (CSAF/VEX, OSV, CVE) at scale.
Rust★ 61Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
NuGet
69Moderatehealth index
package-url/packageurl-dotnet
.NET parser for Package URLs (ECMA-427)
C#★ 17Jul 18, 2026
MITJul 18, 2026 · metrics 1.13.0
PyPI
68Moderatehealth index
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
68Moderatehealth index
voltone/rebar3_sbom
Rebar3 plugin to generate CycloneDX SBoM
Erlang★ 12Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 1.13.0
Go
67Moderatehealth index
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 24Jul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 1.13.0
PyPI
67Moderatehealth index
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/moJul 14, 2026
Custom licenseJul 14, 2026 · metrics 1.13.0
Go
66Moderatehealth index
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0
Go
64Moderatehealth index
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 2Jul 21, 2026
BSD-3-ClauseJul 21, 2026 · metrics 1.13.0
Go
61Moderatehealth index
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 1Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 1.13.0