Sca Collection
Repositories tagged with "sca"
Repositories tagged with "sca"
dependency-track
DependencyTrack
โDependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.โ
scancode-toolkit
aboutcode-org
โ:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!โ
pay
pay-rails
โPayments for Ruby on Rails appsโ
ort
oss-review-toolkit
โA suite of tools to automate software compliance checks.โ
murphysec
murphysecurity
โAn open source tool focused on software supply chain security. ๅขจ่ฒๅฎๅ จไธๆณจไบ่ฝฏไปถไพๅบ้พๅฎๅ จ๏ผๅ ทๅคไธไธ็่ฝฏไปถๆๅๅๆ๏ผSCA๏ผใๆผๆดๆฃๆตใไธไธๆผๆดๅบใโ
dep-scan
owasp-dep-scan
โOWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.โ
OpenSCA-cli
XmirrorSecurity
โOpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community. โ
cdxgen
cdxgen
โCreates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track serverโ
automated-security-helper
awslabs
โASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.โ
log4j-detector
mergebase
โA public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too! TAG_OS_TOOL, OWNER_KELLY, DC_PUBLICโ
ant-application-security-testing-benchmark
alipay
โxAST่ฏไปทไฝ็ณป๏ผ่ฎฉๅฎๅ จๅทฅๅ ทไธๅโ้ป็โ. The xAST evaluation benchmark makes security tools no longer a "black box".โ
aboutcode
aboutcode-org
โ AboutCode project: tools and data to uncover things about code: the provenance, origin, license, and more (packages, security, quality, etc.) of FOSS code. Get started at https://aboutcode.readthedocs.io/ โ
grepmarx
Orange-Cyberdefense
โA source code static analysis platform for AppSec enthusiasts.โ
nist-data-mirror
stevespringett
โA simple Java command-line utility to mirror the CVE JSON data from NIST.โ
scancode.io
aboutcode-org
โScanCode.io is a server to script and automate software composition analysis with pipelines. This project is sponsored by the European Commission, NLnet NGI0, the Google Summer of Code, nexB and others generous sponsors!โ
pwned-deps
mkbhardwas12
โLockfile-first scanner for compromised npm/PyPI/Maven/Cargo/Go/RubyGems packages โ OSV + curated extras feed, SLSA L3, locked-container CIโ
vulnerability-db
AppThreat
โVulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers.โ
drogonsec
filipi86
โHigh-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!โ
