TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Open-source SBOM generation tools?

7 点作者 riyakhanna1983将近 3 年前
One of the compliance requirements of the recent Cybersecurity EO order is to track software bill of materials (SBOM). Curious to know what open-source tools exist to generate SBOM and how accurate they are.

4 条评论

derkoe将近 3 年前
Currently the best one I know of is <a href="https:&#x2F;&#x2F;github.com&#x2F;anchore&#x2F;syft" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;anchore&#x2F;syft</a>. It finds most dependencies even within built artifacts.<p>You can also check out the comments in <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=32104805" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=32104805</a> - the release announcement of Salus (Microsoft)
jupenur将近 3 年前
We weren&#x27;t happy with what was already out there, so we built our own -- <a href="https:&#x2F;&#x2F;github.com&#x2F;mattermost&#x2F;gobom" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;mattermost&#x2F;gobom</a>
jasonrojas将近 3 年前
We use this - <a href="https:&#x2F;&#x2F;dependencytrack.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;dependencytrack.org&#x2F;</a>
chintler将近 3 年前
This[0] was posted a few days ago here.<p>[0] <a href="https:&#x2F;&#x2F;devblogs.microsoft.com&#x2F;engineering-at-microsoft&#x2F;microsoft-open-sources-software-bill-of-materials-sbom-generation-tool&#x2F;" rel="nofollow">https:&#x2F;&#x2F;devblogs.microsoft.com&#x2F;engineering-at-microsoft&#x2F;micr...</a>