全部标签
目录标签

#cyclonedx

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

31 条记录
标签为“cyclonedx”按健康指数排序
Go
98卓越健康指数
anchore/syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
Go★ 9,4652026年8月28日
Apache-2.02026年8月28日 · 指标 2.10.0
Go
98卓越健康指数
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 5702026年7月16日
Apache-2.02026年7月16日 · 指标 2.10.0
Go
96卓越健康指数
anchore/grype
A vulnerability scanner for container images and filesystems
Go★ 12.8K2026年8月27日
Apache-2.02026年8月27日 · 指标 2.10.0
PyPI
95卓越健康指数
CycloneDX/cyclonedx-python
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
Python★ 390↓ 2.2M/月2026年8月27日
Apache-2.02026年8月27日 · 指标 2.10.0
PyPI · npm
94卓越健康指数
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/月2026年7月16日
Apache-2.02026年7月16日 · 指标 2.10.0
Maven · npm
94卓越健康指数
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Kotlin★ 2,0512026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
npm · Maven · NuGet +1
92优秀健康指数
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1,018↓ 745.3K/月2026年7月28日
Apache-2.02026年7月28日 · 指标 2.10.0
Packagist
91优秀健康指数
CycloneDX/cyclonedx-php-composer
Create CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects
PHP★ 87↓ 91.9K/月2026年7月29日
Apache-2.02026年7月29日 · 指标 2.10.0
PyPI
90优秀健康指数
CycloneDX/cyclonedx-python-lib
Functionality and DataModels of OWASP CycloneDX for Python
Python★ 1132026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
npm
89优秀健康指数
janbiasi/rollup-plugin-sbom
Create SBOMs in CycloneDX format for your Vite, Rollup or Rolldown projects with ease
TypeScript★ 23↓ 177.5K/月2026年7月17日
MIT2026年7月17日 · 指标 2.10.0
PyPI
89优秀健康指数
kdeldycke/meta-package-manager
🎁 wraps all package managers with a unifying CLI
Python★ 6092026年7月20日
GPL-2.02026年7月20日 · 指标 2.10.0
PyPI
86优秀健康指数
aboutcode-org/scancode-toolkit
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!
Python · C · Shell★ 2,5832026年7月21日
自定义许可证2026年7月21日 · 指标 2.10.0
Go · PyPI
86优秀健康指数
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 92026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
Maven · npm
86优秀健康指数
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 662026年7月15日
Apache-2.02026年7月15日 · 指标 2.10.0
npm
84优秀健康指数
CycloneDX/cyclonedx-node-module
creates CycloneDX Software-Bill-of-Materials (SBOM) from Node.js-based projects
混合★ 145↓ 76.5K/月2026年9月5日
Apache-2.02026年9月5日 · 指标 2.10.0
PyPI · npm
84优秀健康指数
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1,281↓ 10.9K/月2026年8月24日
MIT2026年8月24日 · 指标 2.10.0
83优秀健康指数
CycloneDX/cyclonedx-cli
CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.
C#★ 5332026年8月21日
Apache-2.02026年8月21日 · 指标 2.10.0
NuGet
83优秀健康指数
CycloneDX/cyclonedx-dotnet-library
.NET library to consume and produce CycloneDX Software Bill of Materials (SBOM)
C#★ 282026年7月22日
Apache-2.02026年7月22日 · 指标 2.10.0
Maven
83优秀健康指数
CycloneDX/cyclonedx-maven-plugin
Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects
Java★ 3752026年7月30日
Apache-2.02026年7月30日 · 指标 2.10.0
Hex
83优秀健康指数
erlef/mix_sbom
Mix task to generate a Software Bill-of-Materials (SBoM) in CycloneDX format
Elixir★ 47↓ 29.6K/月2026年7月17日
自定义许可证2026年7月17日 · 指标 2.10.0
Go
81优秀健康指数
CycloneDX/sbom-utility
Utility that provides an API platform for validating, querying and managing BOM data
Go★ 1632026年9月3日
Apache-2.02026年9月3日 · 指标 2.10.0
Go
81优秀健康指数
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 82026年7月23日
Apache-2.02026年7月23日 · 指标 2.10.0
PyPI
78良好健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
Go
78良好健康指数
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 242026年7月20日
Apache-2.02026年7月20日 · 指标 2.10.0
78良好健康指数
voltone/rebar3_sbom
Rebar3 plugin to generate CycloneDX SBoM
Erlang★ 122026年7月17日
自定义许可证2026年7月17日 · 指标 2.10.0
Go · npm · PyPI
75良好健康指数
KKloudTarus/synapse-ce
Synapse - a governed control plane for software composition analysis, recon, evidence, and reporting. Verify Everything. Trust Nothing.
Go · Python★ 332026年8月6日
Apache-2.02026年8月6日 · 指标 2.10.0
Go
75良好健康指数
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 22026年7月21日
BSD-3-Clause2026年7月21日 · 指标 2.10.0
PyPI · npm
73良好健康指数
aiexponenthq/license-compliance-checker
License Compliance Checker — Multi-ecosystem license + AI model scanner for EU AI Act Article 53 GPAI compliance. SBOM, SARIF, training-data risk. Apache 2.0.
Python · TypeScript★ 1↓ 258/月2026年7月27日
Apache-2.02026年7月27日 · 指标 2.10.0
Go
71良好健康指数
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 252026年9月5日
自定义许可证2026年9月5日 · 指标 2.10.0
Maven
69良好健康指数
MediaMarktSaturn/technolinator
GitHub app for SBOM creation using cdxgen and upload to Dependency-Track
Java★ 242026年7月27日
Apache-2.02026年7月27日 · 指标 2.10.0