Skip to content
Avatar

Highlights

  • Arctic Code Vault Contributor
  • Pro

Organizations

@jenkinsci @maintainers @CycloneDX @package-url @DependencyTrack @ossf

Pinned

  1. Dependency-Track is an intelligent Supply Chain Component Analysis platform that allows organizations to identify and reduce risk from the use of third-party and open source components.

    Java 576 184

  2. Software Bill-of-Material (SBOM) specification designed for use in application security contexts and supply chain component analysis

    XSLT 32 9

  3. A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby

    129 32

  4. Software Component Verification Standard (SCVS)

    Python 47 7

  5. A utility for validating and parsing Common Platform Enumeration (CPE) v2.2 and v2.3 as originally defined by MITRE and maintained by NIST

    Java 14 7

  6. A Java library for calculating CVSSv2 and CVSSv3 scores and vectors

    Java 15 10

2,068 contributions in the last year

Sep Oct Nov Dec Jan Feb Mar Apr May Jun Jul Aug Mon Wed Fri

Contribution activity

August 2020

Created an issue in CycloneDX/specification that received 4 comments

Expand hardware support

CycloneDX has support for components of type 'device'. However, device-specific fields have been left out of the core specification as they are bet…

4 comments

Seeing something unexpected? Take a look at the GitHub profile guide.

You can’t perform that action at this time.