Git Product home page Git Product logo

awesome-sbom's Introduction

awesome-sbom Awesome

A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles

What is SBOM (Software Bill Of Materials) ?

From Wikipedia:

A software bill of materials (SBOM) is a list of components in a piece of software. Software vendors often create products by assembling open source and commercial software components. The SBOM describes the components in a product. It is analogous to a list of ingredients on food packaging: where you might consult a label to avoid foods that may cause an allergies, SBOMs can help companies avoid consumption of software that could harm their organization.

The concept of a BOM is well-established in traditional manufacturing as part of supply chain management. A manufacturer uses a BOM to track the parts it uses to create a product. If defects are later found in a specific part, the BOM makes it easy to locate affected products.

Contents

Official projects

Articles and Blogs

  • Wikipedia - Official Wikipedia Page
  • NTIA - Official National Telecommunications and Information Administration Page
  • What is an SBOM? - The Linux Foundation Article

Tools (and classification)

Tool Build SBOM Analyze SBOM Edit SBOM View SBOM Diff SBOM Import SBOM Translate SBOM Merge SBOM Integrate with Other Tools
AnthonyHarrison SBOM4Python CycloneDX,SPDX
AnthonyHarrison SBOM4Rust CycloneDX,SPDX
AnthonyHarrison SBOM4Files CycloneDX,SPDX
AnthonyHarrison Distro2SBOM CycloneDX,SPDX
AnthonyHarrison SBOMDiff CycloneDX,SPDX CycloneDX,SPDX
AnthonyHarrison SBOM2doc CycloneDX,SPDX CycloneDX,SPDX
AnthonyHarrison SBOM2dot CycloneDX,SPDX CycloneDX,SPDX
AnthonyHarrison SBOMAudit CycloneDX,SPDX CycloneDX,SPDX
AnthonyHarrison SBOM-Manager CycloneDX,SPDX CycloneDX,SPDX
bomber CycloneDX,SPDX CycloneDX,SPDX
CycloneDX Maven Plugin CycloneDX
CycloneDX CLI tool CycloneDX CycloneDX CycloneDX,SPDX CycloneDX
Interlynk SBOM Assembler CycloneDX,SPDX CycloneDX,SPDX CycloneDX,SPDX
Interlynk SBOM Quality Score CycloneDX,SPDX CycloneDX,SPDX CycloneDX,SPDX
Interlynk SBOM Grep CycloneDX,SPDX CycloneDX,SPDX CycloneDX,SPDX
Interlynk SBOM Find & Pull CycloneDX,SPDX CycloneDX,SPDX
Kubernetes SBOM Tool SPDX
Microsoft SBOM tool SPDX
Syft CycloneDX,SPDX CycloneDX,SPDX CycloneDX,SPDX
Snyk SBOM API & CLI CycloneDX,SPDX
Snyk SBOM Checker CycloneDX,SPDX
spdx-sbom-generator SPDX
SwiftBOM CycloneDX,SPDX,SWID
Tern CycloneDX,SPDX
Trivy CycloneDX,SPDX CycloneDX,SPDX CycloneDX,SPDX

Repositories

CycloneDX

SPDX

Community Repositories

Security Tools

  • bomber - bomber is an application that scans SBoMs for security vulnerabilities.

Articles and Blogs

Videos

Slides

Podcasts

None yet, please contribute!

Benchmarks

  • SBOM Benchmark Quickly evaluate SBOM for quality, compliance and errors.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.