Skip to content
View hslatman's full-sized avatar
💭
Gitting around
💭
Gitting around

Organizations

@smallstep @distributit

Block or report hslatman

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

SBOM

19 repositories

An SBOM query language and associated utilities

Go 56 3 Updated Jan 22, 2024

OmniBOR implementation in Go.

Go 10 5 Updated May 21, 2023

Software Supply Chain Security Platform

Go 407 101 Updated Jun 13, 2026

Go linter that checks if package imports are in a list of acceptable packages.

Go 200 19 Updated Mar 6, 2025

A universal SBOM representation in protocol buffers

Go 326 59 Updated Jun 4, 2026

sbomqs: The Comprehensive SBOM Quality & Compliance Tool

Go 294 33 Updated Jun 12, 2026

Utility that provides an API platform for validating, querying and managing BOM data

Go 141 20 Updated Jun 9, 2026

OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, an…

XSLT 517 87 Updated Jun 11, 2026

Format agnostic SBOM tooling

Go 137 19 Updated Nov 20, 2025

Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption

Vue 115 43 Updated Feb 28, 2026

A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)

228 81 Updated Oct 21, 2025

Enrich SBOMs with data from third party services

Go 228 35 Updated May 18, 2026

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

Go 615 54 Updated Feb 10, 2026

Collection of Go packages to work with SPDX files

Go 168 73 Updated Feb 23, 2026

Graphing SBOM's Fast.

Go 732 26 Updated Aug 29, 2025
Go 6 1 Updated Dec 12, 2024
4 Updated Nov 15, 2024

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Java 3,905 748 Updated Jun 12, 2026

Protect against malicious open source packages 🤖

Go 1,076 101 Updated Jun 11, 2026