You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Graph for Understanding Artifact Composition (GUAC) aggregates software security metadata into a high fidelity graph database—normalizing entity identities and mapping standard relationships between them. Querying this graph can drive higher-level organizational outcomes such as audit, policy, risk management, and even developer assistance.
primary_languages
Go
short_term_roadmap
Hardening for a 1.0 release.
long_term_roadmap
Separate parts of GUAC out for individual use:
SBOM parsing
Supply chain graph synthesis
Storage
etc.
proprietary_data
Yes, the tool depends on proprietary data sources
commercial_features
Yes, the tool has a commercial version with different/additional features
capabilities
Identifiers - Use Package-URL (PURL) identifiers
Identifiers - Use SPDX license expressions
Scanning - Analyze package manifests and lockfiles
Scanning - Analyze package files
Scanning - Scan for copyright
Scanning - Scan for license
Scanning - Analyze source code
Scanning - Analyze containers
Scanning - Analyze installed system packages (linux distros)
Scanning - Analyze installed application packages
Scanning - Other analysis
Packages - Inventory packages
Packages - Inventory packages dependencies
Packages - Resolve dependencies
Packages - Navigate or display dependency graph
Compliance - Generate CycloneDX SBOMs
Compliance - Generate SPDX SBOMs
Compliance - Validate CycloneDX SBOM
Compliance - Validate SPDX SBOMs
Compliance - Generate CycloneDX VEX
Compliance - Generate CSAF VEX
Compliance - Generate OpenVex
Compliance - Generate other compliance documents
Policies - Define and check license policies
Policies - Define and check security policies
Policies - Define and check other policies
Data - Database of Package metadata
Data - Database of Package dependency relationships
Data - Database of License obligations
Data - Database of Licenses
Data - Database of Vulnerabilities
License - Help triage license issues
License - Generate license credit and attribution notices
homepage_url
https://guac.sh/
contact_email
[email protected]
code_view_url
https://github.com/guacsec/guac
spdx_license_expression
Apache-2.0
description
Graph for Understanding Artifact Composition (GUAC) aggregates software security metadata into a high fidelity graph database—normalizing entity identities and mapping standard relationships between them. Querying this graph can drive higher-level organizational outcomes such as audit, policy, risk management, and even developer assistance.
primary_languages
Go
short_term_roadmap
Hardening for a 1.0 release.
long_term_roadmap
Separate parts of GUAC out for individual use:
proprietary_data
commercial_features
capabilities
other_capabilities
No response
The text was updated successfully, but these errors were encountered: