Software Alternatives, Accelerators & Startups

Microsoft open sources Salus software bill of materials (SBOM) generation tool

OWASP Dependency-Track The Tidelift Subscription
  1. OWASP Dependency-Track is an intelligent Software Composition Analysis (SCA) platform that allows...
    Pricing:
    • Open Source
    I'm confused. When would I need "https://dependencytrack.org/"? Is it when I've completely lost my marbles and can no longer answer the questions "what does your app run on" and "what are your app's dependencies"? Is the idea that I would then download and install this "dependency tracker", hoping it would give me a list of things I depend on, so that I could inform the end user? What's the use case?

    #Security #Code Analysis #Open Source 19 social mentions

  2. Pro developers get assurances. OSS maintainers get paid.
    There is an open source UI for querying based on SBOM called DependencyTrack (https://dependencytrack.org/). Commercial offerings exist from vendors like TideLift (https://tidelift.com/).

    #Online Services #Email Marketing #Entertainment 25 social mentions

Discuss: Microsoft open sources Salus software bill of materials (SBOM) generation tool

Log in or Post with