SBOM
An SBOM query language and associated utilities
Go linter that checks if package imports are in a list of acceptable packages.
A universal SBOM representation in protocol buffers
sbomqs: The Comprehensive SBOM Quality & Compliance Tool
Utility that provides an API platform for validating, querying and managing BOM data
OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, an…
Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
Collection of Go packages to work with SPDX files
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.