- Chicago
- https://springett.us/
- @stevespringett
Highlights
- Pro
- 9 discussions answered
Block or Report
Block or report stevespringett
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned Loading
-
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
-
CycloneDX/specification Public
Software Bill of Material (SBOM) standard designed for use in application security contexts and supply chain component analysis
-
package-url/purl-spec Public
A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby
-
Software Component Verification Standard (SCVS)
-
CPE-Parser Public
A utility for validating and parsing Common Platform Enumeration (CPE) v2.2 and v2.3 as originally defined by MITRE and maintained by NIST
-
cvss-calculator Public
A Java library for calculating CVSSv2 and CVSSv3 scores and vectors