software-composition-analysis
Tracked open-source repos tagged software-composition-analysis, sorted by stars.
Related topics
Topics that frequently appear alongside software-composition-analysis on the same repo.
Recent risers
Repos created in the last 90 days, tagged software-composition-analysis.
No new repos tagged with this topic in the last 90 days.
- #1
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
★ 7,675+9Star change over the last 7 days - #2
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
★ 4,163+2Star change over the last 7 days - #3
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
★ 4,156+23Star change over the last 7 days - #4
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!
★ 2,613+4Star change over the last 7 days - #5
An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。
★ 1,753+0Star change over the last 7 days - #6
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
★ 1,469+0Star change over the last 7 days - #7
OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
★ 1,127+1Star change over the last 7 days - #8★ 1,103+2Star change over the last 7 days
- #9
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
★ 1,019+0Star change over the last 7 days - #10
Scans your project to determine what components you use
★ 552+2Star change over the last 7 days