全部标签
目录标签

#sbom

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

38 条记录
标签为“sbom”按健康指数排序
Go
85优秀健康指数
anchore/syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
Go★ 9,2622026年7月21日
Apache-2.02026年7月21日 · 指标 1.13.0
Go
85优秀健康指数
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 5702026年7月16日
Apache-2.02026年7月16日 · 指标 1.13.0
Go · npm
83良好健康指数
zarf-dev/zarf
The Airgap Native Package Manager for Kubernetes
Go★ 1,9852026年7月22日
Apache-2.02026年7月22日 · 指标 1.13.0
PyPI · npm
80良好健康指数
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/月2026年7月16日
Apache-2.02026年7月16日 · 指标 1.13.0
Maven · npm
80良好健康指数
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Kotlin★ 2,0512026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
77良好健康指数
microsoft/component-detection
Scans your project to determine what components you use
C#★ 5452026年7月18日
MIT2026年7月18日 · 指标 1.13.0
PyPI
76良好健康指数
CycloneDX/cyclonedx-python-lib
Functionality and DataModels of OWASP CycloneDX for Python
Python★ 1132026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
npm · Maven · NuGet +1
76良好健康指数
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1,012↓ 719.2K/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
npm
76良好健康指数
janbiasi/rollup-plugin-sbom
Create SBOMs in CycloneDX format for your Vite, Rollup or Rolldown projects with ease
TypeScript★ 23↓ 177.5K/月2026年7月17日
MIT2026年7月17日 · 指标 1.13.0
PyPI
75良好健康指数
fsfe/reuse-tool
This is a mirror of https://codeberg.org/fsfe/reuse-tool
Python★ 583↓ 552.1K/月2026年7月21日
自定义许可证2026年7月21日 · 指标 1.13.0
PyPI
75良好健康指数
kdeldycke/meta-package-manager
🎁 wraps all package managers with a unifying CLI
Python★ 6092026年7月20日
GPL-2.02026年7月20日 · 指标 1.13.0
PyPI · npm
74良好健康指数
NuGuardAI/nuguard
opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
Python★ 10↓ 4,954/月2026年7月18日
自定义许可证2026年7月18日 · 指标 1.13.0
npm
72良好健康指数
cyclonedx/cyclonedx-node-module
creates CycloneDX Software-Bill-of-Materials (SBOM) from Node.js-based projects
混合★ 143↓ 84.4K/月2026年7月14日
Apache-2.02026年7月14日 · 指标 1.13.0
Maven · npm
72良好健康指数
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 662026年7月15日
Apache-2.02026年7月15日 · 指标 1.13.0
PyPI
71良好健康指数
aboutcode-org/scancode-toolkit
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!
Python · C · Shell★ 2,5832026年7月21日
自定义许可证2026年7月21日 · 指标 1.13.0
npm
71良好健康指数
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2,247/月2026年7月15日
MIT2026年7月15日 · 指标 1.13.0
Go · PyPI
71良好健康指数
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 92026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
Hex
71良好健康指数
erlef/mix_sbom
Mix task to generate a Software Bill-of-Materials (SBoM) in CycloneDX format
Elixir★ 47↓ 29.6K/月2026年7月17日
自定义许可证2026年7月17日 · 指标 1.13.0
PyPI · npm
71良好健康指数
lgtm-hq/py-lintro
Making linters play nice... Mostly.
Python★ 1↓ 8,269/月2026年7月17日
MIT2026年7月17日 · 指标 1.13.0
NuGet
70良好健康指数
CycloneDX/cyclonedx-dotnet-library
.NET library to consume and produce CycloneDX Software Bill of Materials (SBOM)
C#★ 282026年7月22日
Apache-2.02026年7月22日 · 指标 1.13.0
70良好健康指数
microsoft/sbom-tool
The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.
C#★ 2,0472026年7月17日
MIT2026年7月17日 · 指标 1.13.0
crates.io
69中等健康指数
guacsec/trustify
SBOM analysis platform for storing, correlating, and querying software bill of materials and security advisories (CSAF/VEX, OSV, CVE) at scale.
Rust★ 612026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
NuGet
69中等健康指数
package-url/packageurl-dotnet
.NET parser for Package URLs (ECMA-427)
C#★ 172026年7月18日
MIT2026年7月18日 · 指标 1.13.0
PyPI
68中等健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
68中等健康指数
voltone/rebar3_sbom
Rebar3 plugin to generate CycloneDX SBoM
Erlang★ 122026年7月17日
自定义许可证2026年7月17日 · 指标 1.13.0
Go
67中等健康指数
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 242026年7月20日
Apache-2.02026年7月20日 · 指标 1.13.0
PyPI
67中等健康指数
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/月2026年7月14日
自定义许可证2026年7月14日 · 指标 1.13.0
Go
66中等健康指数
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 82026年7月21日
Apache-2.02026年7月21日 · 指标 1.13.0
Go
64中等健康指数
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 22026年7月21日
BSD-3-Clause2026年7月21日 · 指标 1.13.0
Go
61中等健康指数
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 12026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0