aboutcode-org / aboutcode-org/www.aboutcode.org

POST: a series of PURL sightings

Abierto
#9 0 comentarios 0 reacciones 0 asignados Ver en GitHub
blog
Lenguaje dominante
JavaScript
Estrellas
9
Forks
18
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

I would like to start a series of short posts on organizations, projects and tools using Package-URL (PURL)

Each example will reflect on the PURL ecosystem momentum towards adopting PURL as a "common language" for identifying software packages.

And should come with a simple description and usage. Since PURL adoption spans across SBOM and VEX specs, generation, vulnerability management, license compliance, and threat intelligence, this will highlight its versatility and value.

- [ ] **CycloneDX** — [https://cyclonedx.org/](https://cyclonedx.org/)
- [ ] **SPDX** — [https://spdx.dev/](https://spdx.dev/)
- [ ] **CSAF (Common Security Advisory Framework)** — [https://docs.oasis-open.org/csaf/csaf/v2.0/csaf-v2.0.html](https://docs.oasis-open.org/csaf/csaf/v2.0/csaf-v2.0.html)
- [ ] **OpenVEX** — [https://github.com/openvex/openvex](https://github.com/openvex/openvex)

## Also:

- [ ] **Dependency-Track** — [https://github.com/DependencyTrack/dependency-track](https://github.com/DependencyTrack/dependency-track)
- [ ] **OSS Review Toolkit (ORT)** — [https://github.com/oss-review-toolkit/ort](https://github.com/oss-review-toolkit/ort)
- [ ] Cdxgen — https://github.com/AppThreat/cdxgen and other projects
- [ ] https://github.com/APH10/ projects
- [ ] https://github.com/armijnhemel/ projects
- [ ] https://github.com/oracle/macaron/
- [ ] **cve-bin-tool** — [https://github.com/intel/cve-bin-tool](https://github.com/intel/cve-bin-tool)
- [ ] **GUAC** — [https://github.com/guacsec/guac](https://github.com/guacsec/guac)
- [ ] **Trustification** — [https://github.com/trustification/trustification](https://github.com/trustification/trustification)
- [ ] **Anchore Syft** — [https://github.com/anchore/syft](https://github.com/anchore/syft)
- [ ] **Tern** — [https://github.com/tern-tools/tern](https://github.com/tern-tools/tern)
- [ ] **bom-builder** — [https://github.com/bom-squad/bom-builder](https://github.com/bom-squad/bom-builder)
- [ ] **bom-shelter** — [https://github.com/bom-squad/bom-shelter](https://github.com/bom-squad/bom-shelter)
- [ ] **Docker SBOM CLI Plugin** — [https://github.com/docker/sbom-cli-plugin](https://github.com/docker/sbom-cli-plugin)
- [ ] Amazon inspector - https://docs.aws.amazon.com/inspector/latest/user/sbom-generator-purl-sbom.html

## Other tools and databases

- [ ] **Sonatype OSS Index** https://ossindex.sonatype.org/doc/reference#purl
- [ ] **OSV.dev** — [https://osv.dev/](https://osv.dev/)
- [ ] **deps.dev** https://deps.dev/
- [ ] **GitHub** https://docs.github.com/en/rest/dependency-graph/dependency-submission?apiVersion=2022-11-28&versionId=free-pro-team%40latest&category=dependency-graph&subcategory=sboms
- [ ] **Microsoft** https://github.com/microsoft/sbom-tool
- [ ] **blackduck** https://documentation.blackduck.com/bundle/bh-hub-2025.4/page/SbomTemplates/creatingSbomTemplates.html
- [ ] **Snyk** https://docs.snyk.io/snyk-api/using-specific-snyk-apis/issues-list-issues-for-a-package
- [ ] **Debricked** https://debricked.com/docs/
- [ ] Sbomqs Viewer — https://github.com/advanced-security/sbomqs-viewer

## Other posts and books
- [ ] "Effective Vulnerability Management" Wiley by Chris Hugues
- [ ] CISA
- [ ] CVE.org
- [ ] Tom Alrich efforts
- [ ] TC54
- [ ] BSI
- [ ] Indian Govt.
- [ ] Dutch Govt. https://english.ncsc.nl/binaries/ncsc-en/documenten/publications/2024/july/30/software-bill-of-materials-starter-guide/Software+Bill+of+Materials+Starter+Guide.pdf
- [ ] Inedo https://docs.inedo.com/docs/proget/api/packages

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.