CLI tool and library for generating a Software Bill of Materials from container images and filesystems
-
Updated
Oct 25, 2025 - Go
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
GUAC aggregates software security metadata into a high fidelity graph database.
OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
sbomqs: The Comprehensive SBOM Quality & Compliance Tool
Reliable project licenses detector.
licensechecker (lc) a command line application which scans directories and identifies what software license things are under producing reports as either SPDX, CSV, JSON, XLSX or CLI Tabular output. Dual-licensed under MIT or the UNLICENSE.
Utility that provides an API platform for validating, querying and managing BOM data
Format agnostic SBOM tooling
Automate copyright headers and license files at scale
SBOM Search - Context aware search in SBOM repositories
Tool to inspect and push and SPDX document as an OCI artifact
A lightweight Go library for validating Software Bill of Materials (SBOM) against industry-standard specifications
Add a description, image, and links to the spdx topic page so that developers can more easily learn about it.
To associate your repository with the spdx topic, visit your repo's landing page and select "manage topics."