- Chicago
- https://springett.us/
- @stevespringett
Highlights
- Pro
- 23 discussions answered
Block or Report
Block or report stevespringett
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned
-
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
-
CycloneDX/specification Public
Software Bill of Material (SBOM) standard designed for use in application security contexts and supply chain component analysis
-
package-url/purl-spec Public
A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby
-
Software Component Verification Standard (SCVS)
-
CPE-Parser Public
A utility for validating and parsing Common Platform Enumeration (CPE) v2.2 and v2.3 as originally defined by MITRE and maintained by NIST
-
cvss-calculator Public
A Java library for calculating CVSSv2 and CVSSv3 scores and vectors
1,820 contributions in the last year
Activity overview
Contribution activity
April 2022
Opened 1 pull request in 1 repository
stevespringett/Alpine
1
merged
Created an issue in DependencyTrack/gh-upload-sbom that received 1 comment
Release v1.1.0
There have been a few PRs lately and we need to release v1.1.0 as a result. Not sure how to release new actions. There doesn't appear to be a relea…