FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

software-composition-analysis · GitHub Topics · GitHub

#

software-composition-analysis

Here are 138 public repositories matching this topic...

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

  • Updated Aug 18, 2026
  • Java

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

  • Updated Aug 8, 2026
  • JavaScript

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

  • Updated Aug 19, 2026
  • Java

🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!

  • Updated Aug 19, 2026
  • Python

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

  • Updated Apr 7, 2026
  • Go

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

  • Updated May 2, 2024
  • TypeScript

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.

  • Updated May 15, 2026
  • Go

Protect against malicious open source packages 🤖

  • Updated Aug 16, 2026
  • Go

Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.

  • Updated Mar 12, 2024
  • Python

Scans your project to determine what components you use

  • Updated Aug 19, 2026
  • C#

SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). 🌈

  • Updated Oct 11, 2025
  • Scala

A simple Java command-line utility to mirror the CVE JSON data from NIST.

  • Updated Nov 4, 2022
  • Java

ScanCode.io is a server to script and automate software composition analysis with pipelines. This project is sponsored by the European Commission, NLnet NGI0, the Google Summer of Code, nexB and others generous sponsors!

  • Updated Aug 18, 2026
  • Python

A curated list of Software Component Analysis (SCA) books, courses - free and paid, videos, tools, and tutorials.

  • Updated Nov 26, 2024

Maven plugin that integrates with a Dependency Track server to submit dependency manifests and optionally fail execution when vulnerable dependencies are found.

  • Updated Aug 15, 2026
  • Java

A light-weight app to audit and inventory large codebases for open source license compliance.

  • Updated Aug 19, 2026
  • TypeScript

A scalable server implementation of the OSS Review Toolkit.

  • Updated Aug 19, 2026
  • Kotlin

The SCANOSS SBOM Workbench graphical user interface to scan and audit your source code.

  • Updated Aug 4, 2026
  • TypeScript

Improve this page

Add a description, image, and links to the software-composition-analysis topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the software-composition-analysis topic, visit your repo's landing page and select "manage topics."

Learn more


Back | FazBrowse Home | New Git URL