OpenChain Specification
-
Updated
Jul 3, 2017 - JavaScript
OpenChain Specification
Check a GitHub organization's repositories' license choices
An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Secure Software Supply Chain Lifecycle in Cybersecurity.
📝 Detect what license a project is distributed under
bitbake layer repository for intergrating osselot into the build process
DeltaCode: compare two codebase scans (from ScanCode) to detect significant changes.
See who wrote each line of code in your git repository with interactive reports.
A desktop workbench for OSS Review Toolkit result files.
This repo contains license and copyright analysis results of open source packages. It further contains other license compliance relevant artifacts, which might be of value for others
Cool links, tools & papers related to Open Source Licensing
Curated list of security tools
A light-weight app to audit and inventory large codebases for open source license compliance.
This repo realizes the idea that OSS compliance activities will be less expensive by applying OSS principles
📊 ScanCode Workbench is a desktop app to review and conclude license and origin from code scans generated by ScanCode Toolkit.
A compilation of resources in the software supply chain security domain, with emphasis on open source
Chainloop is an Open Source evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, CSAF files, QA reports, and more.
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
Add a description, image, and links to the oss-compliance topic page so that developers can more easily learn about it.
To associate your repository with the oss-compliance topic, visit your repo's landing page and select "manage topics."