All tags
Catalogue tag

#sbom

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

61 records
Tagged “sbom”Ranked by health index
Maven
83Excellenthealth index
CycloneDX/cyclonedx-maven-plugin
Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects
Java★ 375Jul 30, 2026
Apache-2.0Jul 30, 2026 · metrics 2.10.0
Hex
83Excellenthealth index
erlef/mix_sbom
Mix task to generate a Software Bill-of-Materials (SBoM) in CycloneDX format
Elixir★ 47↓ 29.6K/moJul 17, 2026
Custom licenseJul 17, 2026 · metrics 2.10.0
Go
83Excellenthealth index
liatrio/autogov
Unified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 1Aug 1, 2026
Apache-2.0Aug 1, 2026 · metrics 2.10.0
83Excellenthealth index
microsoft/sbom-tool
The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.
C#★ 2,047Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
Go
81Excellenthealth index
CycloneDX/sbom-utility
Utility that provides an API platform for validating, querying and managing BOM data
Go★ 163Sep 3, 2026
Apache-2.0Sep 3, 2026 · metrics 2.10.0
Go
81Excellenthealth index
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 23, 2026
Apache-2.0Jul 23, 2026 · metrics 2.10.0
crates.io
81Excellenthealth index
guacsec/trustify
SBOM analysis platform for storing, correlating, and querying software bill of materials and security advisories (CSAF/VEX, OSV, CVE) at scale.
Rust★ 61Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
NuGet
81Excellenthealth index
package-url/packageurl-dotnet
.NET parser for Package URLs (ECMA-427)
C#★ 17Jul 18, 2026
MITJul 18, 2026 · metrics 2.10.0
npm · PyPI
80Excellenthealth index
delimit-ai/delimit-mcp-server
The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.
Python · JavaScript★ 21↓ 3,625/moAug 3, 2026
MITAug 3, 2026 · metrics 2.10.0
npm
80Excellenthealth index
quantakrypto/pqc-tools
Open-source post-quantum readiness tooling by quantakrypto
TypeScript★ 9↓ 8,476/moJul 27, 2026
Apache-2.0Jul 27, 2026 · metrics 2.10.0
PyPI
78Goodhealth index
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
Go
78Goodhealth index
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 24Jul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 2.10.0
78Goodhealth index
voltone/rebar3_sbom
Rebar3 plugin to generate CycloneDX SBoM
Erlang★ 12Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 2.10.0
Go · npm · PyPI
75Goodhealth index
KKloudTarus/synapse-ce
Synapse - a governed control plane for software composition analysis, recon, evidence, and reporting. Verify Everything. Trust Nothing.
Go · Python★ 33Aug 6, 2026
Apache-2.0Aug 6, 2026 · metrics 2.10.0
Go
75Goodhealth index
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 2Jul 21, 2026
BSD-3-ClauseJul 21, 2026 · metrics 2.10.0
PyPI
75Goodhealth index
espressif/esp-idf-sbom
ESP-IDF Software Bill of Materials Generation Tool
Python★ 25Jul 28, 2026
Apache-2.0Jul 28, 2026 · metrics 2.10.0
PyPI · npm
73Goodhealth index
aiexponenthq/license-compliance-checker
License Compliance Checker — Multi-ecosystem license + AI model scanner for EU AI Act Article 53 GPAI compliance. SBOM, SARIF, training-data risk. Apache 2.0.
Python · TypeScript★ 1↓ 258/moJul 27, 2026
Apache-2.0Jul 27, 2026 · metrics 2.10.0
Go
71Goodhealth index
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 25Sep 5, 2026
Custom licenseSep 5, 2026 · metrics 2.10.0
Maven
69Goodhealth index
MediaMarktSaturn/technolinator
GitHub app for SBOM creation using cdxgen and upload to Dependency-Track
Java★ 24Jul 27, 2026
Apache-2.0Jul 27, 2026 · metrics 2.10.0
Go · npm
67Goodhealth index
codeswhat/lookout
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 3Jul 16, 2026
Custom licenseJul 16, 2026 · metrics 2.10.0
Go
67Goodhealth index
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 1Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
Go
65Goodhealth index
matteo-sung/lockvet
Explain any lockfile change: bumps release-verified against 22 registries, vulns (OSV), ages, deprecations, typosquats, integrity tampering — 61 formats incl. pdm.lock, vcpkg, mise.lock, build.gradle, pom.xml, go.sum, GitHub Actions, GitLab CI, Dockerfiles, Kubernetes, Helm, SBOMs. CLI + CI gate + MCP server + playground. By an AI agent.
Go★ 0Aug 23, 2026
MITAug 23, 2026 · metrics 2.10.0
crates.io
65Goodhealth index
sebastienrousseau/dtt
Rust crate for date, time, and timezone manipulation. Parse, format, validate, and convert RFC 3339 / ISO 8601 with guaranteed round-trip safety.
Rust★ 7↓ 5,328/moJul 25, 2026
Apache-2.0Jul 25, 2026 · metrics 2.10.0
Go
63Moderatehealth index
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 3Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
Go
60Moderatehealth index
kidoz/go-vulners
Go client library for the Vulners vulnerability database API — search, audit, SBOM, VScanner, and more
Go★ 0Aug 22, 2026
MITAug 22, 2026 · metrics 2.10.0
Go
60Moderatehealth index
olelbis/pswg
Small Go password generator CLI with shell-safe mode and signed release artifacts
Go · HTML · CSS★ 2Jul 26, 2026
MITJul 26, 2026 · metrics 2.10.0
Go
57Moderatehealth index
kidoz/vulners-cli
CLI vulnerability scanner powered by Vulners — search, audit, scan, offline mode
Go★ 6Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
Go
54Moderatehealth index
gitsocial-org/gitsocial
Cross-forge collaboration platform
Go · JavaScript★ 121Sep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
PyPI
53Moderatehealth index
meidielo/aes-256-gcm-python-tool
Reviewable AES-256-GCM educational tool with Argon2id, JSON envelopes, and safe-mode streaming.
Python · HTML★ 0↓ 77/moJul 19, 2026
MITJul 19, 2026 · metrics 2.10.0
npm
36Weakhealth index
absolutejs/vulnerabilities
No repository description published.
TypeScript★ 0↓ 6,697/moAug 5, 2026
Custom licenseAug 5, 2026 · metrics 2.10.0