A Java library for calculating CVSSv2 and CVSSv3 scores and vectors
Repositories
jeremylong repositories
Checkmarx Scan and Result Orchestration
Creates CycloneDX Software Bill-of-Materials (SBOM) from Objective-C and Swift projects that use CocoaPods.
CycloneDX SBOM Model and Utils for Creating and Validating BOMs
Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects
Core functionality of OWASP CycloneDX for JavaScript (Node.js or WebBrowser) written in TypeScript.
Generate CycloneDX Software Bill of Materials (SBOM) from webpack bundles at compile time.
An action to delete workflow runs in a repository.
Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).
Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.
Evaluate source control (GitHub) security posture
Gradle Plugin for Extracting Dependency Information to send to GitHub
Maven plugin for creating GitHub releases
Gradle plugin that adds a 'taskTree' task that prints task dependency tree
:snake: :mag: GuardDog is a CLI tool to Identify malicious PyPI and npm packages
🍻 Default formulae for the missing package manager for macOS
Proof-of-concept for decoupling responsibilities from Dependency-Track's monolithic API server into separate, scalable services, based on Apache Kafka.
Log adapter for use with JCS3 to bind to slf4j.
An extremely easy way to perform background processing in Java. Backed by persistent storage. Open and free for commercial use.
Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc