bill-of-materials

Open-source projects categorized as bill-of-materials
Language: + Java + Go + Python + C#

Top 7 bill-of-material Open-Source Projects

  • dependency-track

    Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

  • Project mention: Show HN: Pre-alpha tool for analyzing spdx SBOMs generated by GitHub | news.ycombinator.com | 2024-04-21

    I've become interested in SBOM recently, and found there were great tools like https://dependencytrack.org/ for CycloneDX SBOMs, but all I have is SPDX SBOMs generated by GitHub.

    I decided to have a go at writing my own dependency track esque tool aiming to integrate with the APIs GitHub provides.

    It's pretty limited in functionality so far, but can give a high level summary of the types of licenses your repository dependencies use, and let you drill down into potentially problematic ones.

    Written in NextJS + mui + sqlite, and using another project of mine to generate most of the API boilerplate/glue (https://github.com/mnahkies/openapi-code-generator)

  • cyclonedx-maven-plugin

    Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects

  • Project mention: Do You Need an SBOM? | dev.to | 2024-05-06

    There are a number of SBOM standards, but we'll focus on the CycloneDX standard here. CycloneDX grew out of the Open Web Application Security Project (OWASP), is licensed under Creative Commons Zero v1 (think a "public domain" license formulated to meet the laws of many countries), and is a widely known and respected standard.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • cyclonedx-gradle-plugin

    Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects

  • cyclonedx-gomod

    Creates CycloneDX Software Bill of Materials (SBOM) from Go modules

  • Project mention: An Overview of Kubernetes Security Projects at KubeCon Europe 2023 | dev.to | 2023-05-22

    CycloneDx-gomod

  • sbomnix

    A suite of utilities to help with software supply chain challenges on nix targets

  • Project mention: Wolfi: A community Linux OS designed for the container and cloud-native era | news.ycombinator.com | 2023-06-27

    I'm not sure what you mean by "non-trivial" but here's a simple discord bot I wrote in python, that I distribute as an OCI image and that is built with Nix for both x86_64 and aarch64 linux via GitHub actions: https://github.com/starcraft66/attention-attention

    There is no SBOM because I didn't bother publishing one but the way Nix builds derivations, you basically get the SBOM for free. You could use a tool like sbomnix[1] to trivially generate an SPDX-format SBOM from the nix derivation that builds the container image.

    1: https://github.com/tiiuae/sbomnix

  • cyclonedx-core-java

    CycloneDX SBOM Model and Utils for Creating and Validating BOMs

  • Project mention: Dependency inventory / dashboard for multiple maven projects | /r/java | 2023-06-08
  • cyclonedx-bom-repo-server

    A BOM repository server for distributing CycloneDX BOMs

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

bill-of-materials related posts

  • Krita fund has 0 corporate support

    7 projects | news.ycombinator.com | 5 Oct 2023
  • Who in your organization is responsible for deciding and implementing AppSec tools? And any recommendations for a reliable alternative for Snyk tools? Thanks!

    1 project | /r/cybersecurity | 8 May 2023
  • SBOM management program?

    1 project | /r/Information_Security | 4 May 2023
  • Go, SBOM and DependencyTrack

    2 projects | /r/golang | 17 Jan 2023
  • How to Automate the Software Bill of Materials (SBOM)

    1 project | dev.to | 17 Nov 2022
  • How to create SBOMs in Java with Maven and Gradle

    4 projects | dev.to | 1 Nov 2022
  • Looking for an alternative to gradle dependency tree

    2 projects | /r/androiddev | 8 Sep 2022
  • A note from our sponsor - InfluxDB
    www.influxdata.com | 7 May 2024
    Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality. Learn more →

Index

What are some of the best open-source bill-of-material projects? This list will help you:

Project Stars
1 dependency-track 2,335
2 cyclonedx-maven-plugin 273
3 cyclonedx-gradle-plugin 140
4 cyclonedx-gomod 124
5 sbomnix 97
6 cyclonedx-core-java 68
7 cyclonedx-bom-repo-server 64

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com