You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
this tool is still in early-development stage. (POC done/positive)
Looking for funding, contributors and champions.
VISION: Create CycloneDX Software Bill of Materials (SBOM) from esbuild projects.
Still undecided whether this will be a plugin for esbuild that hooks into the build process,
or a tool that analyses build metadata after the build run.
primary_languages
undecided, could be either JavaScript/TypeScript or Go-lang
This uses the linkages generated by esbuild to create a dependency graph which only contain the dependencies that are actually used (after tree-shaking)
proprietary_data
Yes, the tool depends on proprietary data sources
commercial_features
Yes, the tool has a commercial version with different/additional features
capabilities
Identifiers - Use Package-URL (PURL) identifiers
Identifiers - Use SPDX license expressions
Scanning - Analyze package manifests and lockfiles
Scanning - Analyze package files
Scanning - Scan for copyright
Scanning - Scan for license
Scanning - Analyze source code
Scanning - Analyze containers
Scanning - Analyze installed system packages (linux distros)
Scanning - Analyze installed application packages
Scanning - Other analysis
Packages - Inventory packages
Packages - Inventory packages dependencies
Packages - Resolve dependencies
Packages - Navigate or display dependency graph
Compliance - Generate CycloneDX SBOMs
Compliance - Generate SPDX SBOMs
Compliance - Validate CycloneDX SBOM
Compliance - Validate SPDX SBOMs
Compliance - Generate CycloneDX VEX
Compliance - Generate CSAF VEX
Compliance - Generate OpenVex
Compliance - Generate other compliance documents
Policies - Define and check license policies
Policies - Define and check security policies
Policies - Define and check other policies
Data - Database of Package metadata
Data - Database of Package dependency relationships
Data - Database of License obligations
Data - Database of Licenses
Data - Database of Vulnerabilities
License - Help triage license issues
License - Generate license credit and attribution notices
homepage_url
https://github.com/CycloneDX/cyclonedx-esbuild#readme-ov-file
contact_email
jan.kowalleck [at] owasp.org
code_view_url
https://github.com/CycloneDX/cyclonedx-esbuild
spdx_license_expression
Apache-2.0
description
Note
this tool is still in early-development stage. (POC done/positive)
Looking for funding, contributors and champions.
VISION: Create CycloneDX Software Bill of Materials (SBOM) from esbuild projects.
Still undecided whether this will be a plugin for esbuild that hooks into the build process,
or a tool that analyses build metadata after the build run.
primary_languages
undecided, could be either JavaScript/TypeScript or Go-lang
short_term_roadmap
nothing planned. looking for contributors and champions.
see CycloneDX/cyclonedx-esbuild#4
long_term_roadmap
all things are community efforts - come and help/contribute
VISION:
proprietary_data
commercial_features
capabilities
other_capabilities
No response
The text was updated successfully, but these errors were encountered: