aboutcode-org / aboutcode-org/www.aboutcode.org

POST: a series of PURL sightings

Aberta
#9 0 comentários 0 reações 0 responsáveis Ver no GitHub
blog
Linguagem predominante
JavaScript
Estrelas
9
Forks
18
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

I would like to start a series of short posts on organizations, projects and tools using Package-URL (PURL)

Each example will reflect on the PURL ecosystem momentum towards adopting PURL as a "common language" for identifying software packages.

And should come with a simple description and usage. Since PURL adoption spans across SBOM and VEX specs, generation, vulnerability management, license compliance, and threat intelligence, this will highlight its versatility and value.

- [ ] **CycloneDX** — [https://cyclonedx.org/](https://cyclonedx.org/)
- [ ] **SPDX** — [https://spdx.dev/](https://spdx.dev/)
- [ ] **CSAF (Common Security Advisory Framework)** — [https://docs.oasis-open.org/csaf/csaf/v2.0/csaf-v2.0.html](https://docs.oasis-open.org/csaf/csaf/v2.0/csaf-v2.0.html)
- [ ] **OpenVEX** — [https://github.com/openvex/openvex](https://github.com/openvex/openvex)

## Also:

- [ ] **Dependency-Track** — [https://github.com/DependencyTrack/dependency-track](https://github.com/DependencyTrack/dependency-track)
- [ ] **OSS Review Toolkit (ORT)** — [https://github.com/oss-review-toolkit/ort](https://github.com/oss-review-toolkit/ort)
- [ ] Cdxgen — https://github.com/AppThreat/cdxgen and other projects
- [ ] https://github.com/APH10/ projects
- [ ] https://github.com/armijnhemel/ projects
- [ ] https://github.com/oracle/macaron/
- [ ] **cve-bin-tool** — [https://github.com/intel/cve-bin-tool](https://github.com/intel/cve-bin-tool)
- [ ] **GUAC** — [https://github.com/guacsec/guac](https://github.com/guacsec/guac)
- [ ] **Trustification** — [https://github.com/trustification/trustification](https://github.com/trustification/trustification)
- [ ] **Anchore Syft** — [https://github.com/anchore/syft](https://github.com/anchore/syft)
- [ ] **Tern** — [https://github.com/tern-tools/tern](https://github.com/tern-tools/tern)
- [ ] **bom-builder** — [https://github.com/bom-squad/bom-builder](https://github.com/bom-squad/bom-builder)
- [ ] **bom-shelter** — [https://github.com/bom-squad/bom-shelter](https://github.com/bom-squad/bom-shelter)
- [ ] **Docker SBOM CLI Plugin** — [https://github.com/docker/sbom-cli-plugin](https://github.com/docker/sbom-cli-plugin)
- [ ] Amazon inspector - https://docs.aws.amazon.com/inspector/latest/user/sbom-generator-purl-sbom.html

## Other tools and databases

- [ ] **Sonatype OSS Index** https://ossindex.sonatype.org/doc/reference#purl
- [ ] **OSV.dev** — [https://osv.dev/](https://osv.dev/)
- [ ] **deps.dev** https://deps.dev/
- [ ] **GitHub** https://docs.github.com/en/rest/dependency-graph/dependency-submission?apiVersion=2022-11-28&versionId=free-pro-team%40latest&category=dependency-graph&subcategory=sboms
- [ ] **Microsoft** https://github.com/microsoft/sbom-tool
- [ ] **blackduck** https://documentation.blackduck.com/bundle/bh-hub-2025.4/page/SbomTemplates/creatingSbomTemplates.html
- [ ] **Snyk** https://docs.snyk.io/snyk-api/using-specific-snyk-apis/issues-list-issues-for-a-package
- [ ] **Debricked** https://debricked.com/docs/
- [ ] Sbomqs Viewer — https://github.com/advanced-security/sbomqs-viewer

## Other posts and books
- [ ] "Effective Vulnerability Management" Wiley by Chris Hugues
- [ ] CISA
- [ ] CVE.org
- [ ] Tom Alrich efforts
- [ ] TC54
- [ ] BSI
- [ ] Indian Govt.
- [ ] Dutch Govt. https://english.ncsc.nl/binaries/ncsc-en/documenten/publications/2024/july/30/software-bill-of-materials-starter-guide/Software+Bill+of+Materials+Starter+Guide.pdf
- [ ] Inedo https://docs.inedo.com/docs/proget/api/packages

Guia de contribuição

Nenhum guia de contribuição indexado para este repositório

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.