sbom-tool VS osv-scanner

Compare sbom-tool vs osv-scanner and see what are their differences.

sbom-tool

The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts. (by microsoft)

osv-scanner

Vulnerability scanner written in Go which uses the data provided by https://osv.dev (by google)
Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
sbom-tool osv-scanner
8 10
1,438 5,825
6.1% 1.9%
8.9 9.6
4 days ago 5 days ago
C# Go
MIT License Apache License 2.0
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

sbom-tool

Posts with mentions or reviews of sbom-tool. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-04-25.

osv-scanner

Posts with mentions or reviews of osv-scanner. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-04-25.

What are some alternatives?

When comparing sbom-tool and osv-scanner you can also consider the following projects:

cyclonedx-gradle-plugin - Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects

trivy - Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

ort - A suite of tools to automate software compliance checks.

betterscan-ce - Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners + OpenAI GPT with One Report (Code, IaC) - Betterscan Community Edition (CE)

cyclonedx-bom-repo-server - A BOM repository server for distributing CycloneDX BOMs

osv.dev - Open source vulnerability DB and triage service.

cyclonedx-maven-plugin - Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects

apko - Build OCI images from APK packages directly without Dockerfile

awesome-sbom - A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles

maloss - Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages

cyclonedx-gomod - Creates CycloneDX Software Bill of Materials (SBOM) from Go modules

melange - build APKs from source code