全部标签
目录标签

#software-composition-analysis

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

6 条记录
标签为“software-composition-analysis”按健康指数排序
Maven
94卓越健康指数
dependency-check/DependencyCheck
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
Java★ 7,6722026年8月28日
Apache-2.02026年8月28日 · 指标 2.10.0
92优秀健康指数
microsoft/component-detection
Scans your project to determine what components you use
C#★ 5452026年7月18日
MIT2026年7月18日 · 指标 2.10.0
PyPI
86优秀健康指数
aboutcode-org/scancode-toolkit
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!
Python · C · Shell★ 2,5832026年7月21日
自定义许可证2026年7月21日 · 指标 2.10.0
Maven · npm
86优秀健康指数
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 662026年7月15日
Apache-2.02026年7月15日 · 指标 2.10.0
PyPI · npm
73良好健康指数
aiexponenthq/license-compliance-checker
License Compliance Checker — Multi-ecosystem license + AI model scanner for EU AI Act Article 53 GPAI compliance. SBOM, SARIF, training-data risk. Apache 2.0.
Python · TypeScript★ 1↓ 258/月2026年7月27日
Apache-2.02026年7月27日 · 指标 2.10.0
Go
67良好健康指数
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 12026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0