3 ms·
Ask HN: Open-source SBOM generation tools?
One of the compliance requirements of the recent Cybersecurity EO order is to track software bill of materials (SBOM). Curious to know what open-source tools exist to generate SBOM and how accurate they are.
- jasonrojas 4y agoWe use this - https://dependencytrack.org/ https://dependencytrack.org/
- chintler 4y agoThis[0] was posted a few days ago here. [0] https://devblogs.microsoft.com/engineering-at-microsoft/microsoft-open-sources-software-bill-of-materials-sbom-generation-tool/ https://devblogs.microsoft.com/engineering-at-microsoft/micr...
- jupenur 4y agoWe weren't happy with what was already out there, so we built our own -- https://github.com/mattermost/gobom https://github.com/mattermost/gobom
- derkoe 4y agoCurrently the best one I know of is https://github.com/anchore/syft https://github.com/anchore/syft. It finds most dependencies even within built artifacts. You can also check out the comments in https://news.ycombinator.com/item?id=32104805 https://news.ycombinator.com/item?id=32104805 - the release announcement of Salus (Microsoft)