Open Issues Need Help
View All on GitHub Generation Context: say that these SBOMs are pre-build source analysis, and stop inventing a tool version about 2 months ago
enhancement good first issue
Software composition analysis CLI — lockfile-first dependency scanning across seven ecosystems, checked against OSV, with SARIF and CycloneDX output.
Python
#cli#cyclonedx#dependency-scanning#developer-tools#osv#python#sarif#sbom#sca#security#supply-chain-security#vulnerability-scanner
Malicious packages are indistinguishable from ordinary CVEs in the table renderer about 2 months ago
bug good first issue
Software composition analysis CLI — lockfile-first dependency scanning across seven ecosystems, checked against OSV, with SARIF and CycloneDX output.
Python
#cli#cyclonedx#dependency-scanning#developer-tools#osv#python#sarif#sbom#sca#security#supply-chain-security#vulnerability-scanner