aboutcode-org / aboutcode-org/workshop
Tool name: SecObserve
- 主要語言
- 沒有語言資料
- 星號
- 4
- 分支
- 0
- PR 合併指標
- 30 天內沒有已合併 PR
描述
### homepage_url
https://secobserve.github.io/SecObserve/
### contact_email
stefan@fleckenstein.co.uk
### code_view_url
https://github.com/SecObserve/SecObserve
### spdx_license_expression
BSD-3-Clause
### description
SecObserve is an open source vulnerability and license management system for software development teams and cloud environments. It supports a variety of open source vulnerability scanners and integrates easily into CI/CD pipelines.
### primary_languages
Python/Django, TypeScript/React
### short_term_roadmap
- Support for multi-level assessments of vulnerabilities in products based on platforms
- Prioritisation of vulnerabilities based on CVSS, EPSS and exploitiblity information
- More flexible notifications for new vulnerabilities
- More flexible rules and policies, possibly integrating Open Policy Agent
- Support for ScanCode and OSS Review Toolkit
- Support more vulnerability scanners, e.g. for cloud infrastructure like Kubernetes
### long_term_roadmap
A long-term roadmap is not yet defined. It will heavily depend on requirements of the users.
### proprietary_data
- [ ] Yes, the tool depends on proprietary data sources
### commercial_features
- [ ] Yes, the tool has a commercial version with different/additional features
### capabilities
- [x] Identifiers - Use Package-URL (PURL) identifiers
- [x] Identifiers - Use SPDX license expressions
- [ ] Scanning - Analyze package manifests and lockfiles
- [ ] Scanning - Analyze package files
- [ ] Scanning - Scan for copyright
- [ ] Scanning - Scan for license
- [ ] Scanning - Analyze source code
- [ ] Scanning - Analyze containers
- [ ] Scanning - Analyze installed system packages (linux distros)
- [ ] Scanning - Analyze installed application packages
- [ ] Scanning - Other analysis
- [ ] Packages - Inventory packages
- [ ] Packages - Inventory packages dependencies
- [ ] Packages - Resolve dependencies
- [ ] Packages - Navigate or display dependency graph
- [ ] Compliance - Generate CycloneDX SBOMs
- [ ] Compliance - Generate SPDX SBOMs
- [x] Compliance - Validate CycloneDX SBOM
- [x] Compliance - Validate SPDX SBOMs
- [x] Compliance - Generate CycloneDX VEX
- [x] Compliance - Generate CSAF VEX
- [x] Compliance - Generate OpenVex
- [ ] Compliance - Generate other compliance documents
- [x] Policies - Define and check license policies
- [x] Policies - Define and check security policies
- [ ] Policies - Define and check other policies
- [ ] Data - Database of Package metadata
- [ ] Data - Database of Package dependency relationships
- [ ] Data - Database of License obligations
- [ ] Data - Database of Licenses
- [ ] Data - Database of Vulnerabilities
- [x] License - Help triage license issues
- [ ] License - Generate license credit and attribution notices
- [ ] License - Generate source code redistribution lists
- [ ] Vulnerabilities - Detect vulnerable code in packages
- [x] Vulnerabilities - Find known vulnerabilities for package
- [ ] Vulnerabilities - Determine reachable vulnerabilities
- [x] Vulnerabilities - Help triage vulnerabilities
- [ ] Binaries - Analyze binaries
- [ ] Binaries - Analyze ELF binaries
- [ ] Binaries - Analyze Windows binaries
- [ ] Binaries - Analyze firmware binaries
- [ ] Binaries - Analyze Other binaries
- [ ] Matching - Match source code
- [ ] Matching - Match binary code
- [ ] Tracing - Trace code execution
- [ ] Tracing - Trace build
- [ ] Code Security - Analyze code statically (SAST/linting)
- [ ] Code Security - Analyze code dynamically (DAST)
- [x] Download - Source package
- [ ] Download - Source repositories
- [ ] Download - Binary package
- [x] Deployment - Deployable as containers (Docker/OCI/k8s/etc)
- [x] Deployment - Deployable in CI/CD pipelines
- [ ] Deployment - Deployable as a library
- [ ] Run - Run as a command line tool
- [x] Run - Run as a web application
- [x] Run - Run as an API service
### other_capabilities
Ingest the results of various vulnerability scanners (SAST, DAST, SCA, secrets, cloud infrastructure)
貢獻指南
這個儲存庫沒有索引到貢獻指南
評估
這個 Issue 還沒有評估資料。