A suite of tools to automate software compliance checks.
-
Updated
May 21, 2024 - Kotlin
A suite of tools to automate software compliance checks.
Chainloop is an Open Source evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, CSAF files, QA reports, and more.
This repo contains license and copyright analysis results of open source packages. It further contains other license compliance relevant artifacts, which might be of value for others
A desktop workbench for OSS Review Toolkit result files.
See who wrote each line of code in your git repository with interactive reports.
A light-weight app to audit and inventory large codebases for open source license compliance.
🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase, the Google Summer of Code, Azure credits, nexB and others generous sponsors!
bitbake layer repository for intergrating osselot into the build process
This repo realizes the idea that OSS compliance activities will be less expensive by applying OSS principles
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
📊 ScanCode Workbench is a desktop app to review and conclude license and origin from code scans generated by ScanCode Toolkit.
An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Secure Software Supply Chain Lifecycle in Cybersecurity.
Curated list of security tools
project barista - open source license and vulnerability management
DeltaCode: compare two codebase scans (from ScanCode) to detect significant changes.
A compilation of resources in the software supply chain security domain, with emphasis on open source
Cool links, tools & papers related to Open Source Licensing
Add a description, image, and links to the oss-compliance topic page so that developers can more easily learn about it.
To associate your repository with the oss-compliance topic, visit your repo's landing page and select "manage topics."