A suite of tools to automate software compliance checks.
-
Updated
Jun 1, 2024 - Kotlin
A suite of tools to automate software compliance checks.
A desktop workbench for OSS Review Toolkit result files.
A light-weight app to audit and inventory large codebases for open source license compliance.
This repo contains license and copyright analysis results of open source packages. It further contains other license compliance relevant artifacts, which might be of value for others
Chainloop is an Open Source evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, CSAF files, QA reports, and more.
🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase, the Google Summer of Code, Azure credits, nexB and others generous sponsors!
See who wrote each line of code in your git repository with interactive reports.
bitbake layer repository for intergrating osselot into the build process
This repo realizes the idea that OSS compliance activities will be less expensive by applying OSS principles
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
📊 ScanCode Workbench is a desktop app to review and conclude license and origin from code scans generated by ScanCode Toolkit.
An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Secure Software Supply Chain Lifecycle in Cybersecurity.
Curated list of security tools
project barista - open source license and vulnerability management
DeltaCode: compare two codebase scans (from ScanCode) to detect significant changes.
A compilation of resources in the software supply chain security domain, with emphasis on open source
Cool links, tools & papers related to Open Source Licensing
Add a description, image, and links to the oss-compliance topic page so that developers can more easily learn about it.
To associate your repository with the oss-compliance topic, visit your repo's landing page and select "manage topics."