A vulnerability scanner for container images and filesystems
-
Updated
Dec 17, 2025 - Go
A vulnerability scanner for container images and filesystems
GUAC aggregates software security metadata into a high fidelity graph database.
Creates CycloneDX Software Bill of Materials (SBOM) from Go modules
A tool to create, transform and attest VEX metadata
Utility that provides an API platform for validating, querying and managing BOM data
vexctl is a tool to attest VEX impact statements
Generates VEX documents by parsing the Kubernetes SecurityContext configuration
A lightweight Go library for validating Software Bill of Materials (SBOM) against industry-standard specifications
GitHub Action for SecureSBOM
Add a description, image, and links to the vex topic page so that developers can more easily learn about it.
To associate your repository with the vex topic, visit your repo's landing page and select "manage topics."