aboutcode-org / aboutcode-org/www.aboutcode.org

POST: a series of PURL sightings

Offen
#9 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
blog
Vorherrschende Sprache
JavaScript
Sterne
9
Forks
18
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

I would like to start a series of short posts on organizations, projects and tools using Package-URL (PURL)

Each example will reflect on the PURL ecosystem momentum towards adopting PURL as a "common language" for identifying software packages.

And should come with a simple description and usage. Since PURL adoption spans across SBOM and VEX specs, generation, vulnerability management, license compliance, and threat intelligence, this will highlight its versatility and value.

- [ ] **CycloneDX** — [https://cyclonedx.org/](https://cyclonedx.org/)
- [ ] **SPDX** — [https://spdx.dev/](https://spdx.dev/)
- [ ] **CSAF (Common Security Advisory Framework)** — [https://docs.oasis-open.org/csaf/csaf/v2.0/csaf-v2.0.html](https://docs.oasis-open.org/csaf/csaf/v2.0/csaf-v2.0.html)
- [ ] **OpenVEX** — [https://github.com/openvex/openvex](https://github.com/openvex/openvex)

## Also:

- [ ] **Dependency-Track** — [https://github.com/DependencyTrack/dependency-track](https://github.com/DependencyTrack/dependency-track)
- [ ] **OSS Review Toolkit (ORT)** — [https://github.com/oss-review-toolkit/ort](https://github.com/oss-review-toolkit/ort)
- [ ] Cdxgen — https://github.com/AppThreat/cdxgen and other projects
- [ ] https://github.com/APH10/ projects
- [ ] https://github.com/armijnhemel/ projects
- [ ] https://github.com/oracle/macaron/
- [ ] **cve-bin-tool** — [https://github.com/intel/cve-bin-tool](https://github.com/intel/cve-bin-tool)
- [ ] **GUAC** — [https://github.com/guacsec/guac](https://github.com/guacsec/guac)
- [ ] **Trustification** — [https://github.com/trustification/trustification](https://github.com/trustification/trustification)
- [ ] **Anchore Syft** — [https://github.com/anchore/syft](https://github.com/anchore/syft)
- [ ] **Tern** — [https://github.com/tern-tools/tern](https://github.com/tern-tools/tern)
- [ ] **bom-builder** — [https://github.com/bom-squad/bom-builder](https://github.com/bom-squad/bom-builder)
- [ ] **bom-shelter** — [https://github.com/bom-squad/bom-shelter](https://github.com/bom-squad/bom-shelter)
- [ ] **Docker SBOM CLI Plugin** — [https://github.com/docker/sbom-cli-plugin](https://github.com/docker/sbom-cli-plugin)
- [ ] Amazon inspector - https://docs.aws.amazon.com/inspector/latest/user/sbom-generator-purl-sbom.html

## Other tools and databases

- [ ] **Sonatype OSS Index** https://ossindex.sonatype.org/doc/reference#purl
- [ ] **OSV.dev** — [https://osv.dev/](https://osv.dev/)
- [ ] **deps.dev** https://deps.dev/
- [ ] **GitHub** https://docs.github.com/en/rest/dependency-graph/dependency-submission?apiVersion=2022-11-28&versionId=free-pro-team%40latest&category=dependency-graph&subcategory=sboms
- [ ] **Microsoft** https://github.com/microsoft/sbom-tool
- [ ] **blackduck** https://documentation.blackduck.com/bundle/bh-hub-2025.4/page/SbomTemplates/creatingSbomTemplates.html
- [ ] **Snyk** https://docs.snyk.io/snyk-api/using-specific-snyk-apis/issues-list-issues-for-a-package
- [ ] **Debricked** https://debricked.com/docs/
- [ ] Sbomqs Viewer — https://github.com/advanced-security/sbomqs-viewer

## Other posts and books
- [ ] "Effective Vulnerability Management" Wiley by Chris Hugues
- [ ] CISA
- [ ] CVE.org
- [ ] Tom Alrich efforts
- [ ] TC54
- [ ] BSI
- [ ] Indian Govt.
- [ ] Dutch Govt. https://english.ncsc.nl/binaries/ncsc-en/documenten/publications/2024/july/30/software-bill-of-materials-starter-guide/Software+Bill+of+Materials+Starter+Guide.pdf
- [ ] Inedo https://docs.inedo.com/docs/proget/api/packages

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.