nexB

nexB

Geek Repo

Location:California, USA

Home Page:https://nexb.com

Github PK Tool:Github PK Tool

nexB's repositories

scancode-toolkit

:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase, the Google Summer of Code, Azure credits, nexB and others generous sponsors!

vulnerablecode

A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/

Language:PythonLicense:Apache-2.0Stargazers:509Issues:23Issues:918

aboutcode

AboutCode project: tools and data to uncover things about code: the provenance, origin, license, and more (packages, security, quality, etc.) of FOSS code

scancode.io

ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ Google Summer of Code, nexB and others generous sponsors!

Language:PythonLicense:Apache-2.0Stargazers:98Issues:14Issues:812

license-expression

Utility library to parse, normalize and compare License expressions for Python using a boolean logic engine. For expressions using SPDX or any other license id scheme.

Language:PythonLicense:NOASSERTIONStargazers:56Issues:15Issues:55

container-inspector

container-inspector is a suite of analysis utilities and command line tools for Docker container images, their layers and how these relate to each other. It can also handle OCI images and Dockerfiles.

extractcode

A mostly universal file extraction library and CLI tool to extract almost any archive in a reasonably safe way on Linux, macOS and Windows.

purldb

Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Chat is at https://gitter.im/aboutcode-org/discuss

scancode-licensedb

A free and open database of all the licenses, in particular all the open source software licenses

univers

Parse and compare all the package versions and all the ranges. From debian, npm, pypi, ruby and more. Process all the version range specs and expressions. This project is sponsored by an NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ , the Google Summer of Code, nexB and others generous sponsors!

dejacode

Automate open source license compliance and ensure software supply chain integrity

Language:PythonLicense:AGPL-3.0Stargazers:19Issues:7Issues:96

pip-requirements-parser

a mostly correct pip requirements parsing library

Language:PythonLicense:MITStargazers:17Issues:5Issues:12

debian-inspector

A python library to parse Debian deb822-style control and copyright files and all related Debian, Ubuntu and Debian-derivative manifest and metadata files, an alternative approach to python-debian.

cwe2

Common weakness enumeration library for Python (maintained fork of https://github.com/Julian-Nash/cwe )

Language:PythonLicense:MITStargazers:11Issues:2Issues:4

fetchcode

A library to reliably fetch code via HTTP, FTP and version control systems. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ Google Summer of Code, nexB and others generous sponsors!

saneyaml

Cleaner, simpler, safer and saner YAML parsing/serialization in Python, for YAML meant to be readable first, on top of PyYAML

scancode-action

Run ScanCode.io pipelines from your Workflows

dependency-inspector

A general purpose, mostly universal software package dependency resolver.

Language:GoLicense:Apache-2.0Stargazers:2Issues:0Issues:0

scancode-plugins

A set of plugins either delivered as builtin scancode-toolkit or extra plugins

aboutcode-cyclonedx-taxonomy

AboutCode CycloneDX Property Taxonomy

go-inspector

An inspector for Go language-based source, binaries, packages, dependencies and metadata

popular-repo-scan-tests

A repository with download urls and reference data for popular packages, to test scan results for them.

Language:PythonStargazers:0Issues:0Issues:0

scancode.io-reference-scans

A set of reference scans with ScanCode.io updated with each new release to track quality and performance progress over time.

Language:PythonStargazers:0Issues:0Issues:0

ScoreCode

A library to fetch and store OpenSSF Scorecard data.

Language:PythonLicense:Apache-2.0Stargazers:0Issues:0Issues:0

source-inspector

Tools to inspect source code and code symbols

Language:CStargazers:0Issues:4Issues:3
Language:PythonStargazers:0Issues:0Issues:0