Apps tagged with 'sbom'

All apps in Apps tagged with 'sbom' category. Use the filters below to narrow down your search. 
Copy a direct link to this comment to your clipboard
  1. Software supply chain attacks are on the rise and with it, the need to build transparent, evidence-based trust in software.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Mac
    • Linux
    • Online
    • Google Chrome
    • Software as a Service (SaaS)
    Scribe Security screenshot 1
    2 alternatives
  2. ReARM icon
     1 like

    ReARM is an abbreviation for "Reliza's Artifact and Release Management". It is a Release Governance Platform to manage lifecycle for product and component releases and organize release metadata, including SBOMs, xBOMs, other security artifacts, vulnerability...

    Cost / License

    Platforms

    • Online
    • Self-Hosted
    • Software as a Service (SaaS)
    • Docker
    Changes in SBOM components detected by ReARM
    Findings showing for a release in ReARM
  3. Mend.io icon
     7 likes

    Mend.io offers the first AI native application security platform, purpose-built to secure AI-generated code and embedded AI components. Our unified platform enables companies to manage application risk effectively in modern software development.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Online
    • Self-Hosted
    • Software as a Service (SaaS)
    Mend.io screenshot 1
    Mend.io screenshot 1
    Mend.io screenshot 2
    30 alternatives
  4. European artifact repository SaaS for secure software supply chains, with package repositories, SBOMs, vulnerability visibility, access control, and CRA-relevant workflows.

    Cost / License

    • Paid
    • Proprietary

    Application type

    Platforms

    • Online
    • Software as a Service (SaaS)
    Explore container repositories with namespaces, tags, digests, and metadata. Craftifact shows platform information, image size, and upload history for full transparency.
    Browse artifacts stored in a repository and inspect detailed metadata such as uploader, timestamps, download history, and repository path.
    Generate scoped API tokens for Maven, Python, npm, go, and OCI registries. Tokens can have configurable expiration times and are ideal for CI/CD pipelines, build systems, and automated deployments.
    +9
    Create robot accounts with dedicated access tokens for CI/CD workflows, automated builds, and deployments with configurable permissions and token rotation.
    8 alternatives
  5. sbomify icon
     Like

    sbomify is the trust center for your software supply chain. Store every SBOM and compliance document in one place, track them across products and releases, and share them with customers and regulators on demand. CycloneDX and SPDX, built for EU CRA compliance.

    Cost / License

    Platforms

    • Online
    • Linux
    • Docker
    sbomify screenshot 1
    sbomify screenshot 1
    sbomify screenshot 2
    +13
    sbomify screenshot 3
  6. Generates SBOMs during CI from lockfiles, containers, and directories using native tooling with ecosystem coverage, metadata enrichment, trusted outputs, and OIDC publishing.

    Cost / License

    Platforms

    • Linux
    • Docker
    sbomify action screenshot 1
    1 alternatives
  7. SCANOSS icon
     Like

    SCANOSS is the first affordable, open OSS Inventory & Intelligence platform that was built specifically for modern DevSecOps and supply chains. Empowering them to deliver greater license, security, quality and provenance visibility and control for DevSecOps teams and their...

    Cost / License

    • Freemium
    • Open Source (MIT)

    Application type

    Platforms

    • Linux
    • Windows
    • Mac
    • Self-Hosted
    • Python
    SCANOSS screenshot 1
    SCANOSS screenshot 1
    2 alternatives