Node fetch with hard size, compression-ratio and time limits. Stops gzip bombs mid-stream.
Top BOM GitHub Repositories & Tools (2026)
Discover the most starred and trending open source tools tagged with #bom.
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
A suite of tools to automate software compliance checks.
π₯ Insanely fast native C++, Swift or Kotlin modules with a statically compiled binding layer to JSI
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-of-Materials (SBOM) for supported binaries.
Catalogue all images of a Kubernetes cluster to multiple targets with Syft
A secure, high-performance, multi-tenant platform for remote App βHostingβ and βComputingβ
The Airgap Native Package Manager for Kubernetes
ReARM - Release Governance Platform
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.