Show HN: Pre-alpha tool for analyzing spdx SBOMs generated by GitHub

https://github.com/mnahkies/spdx-dependency-track
by mnahkies • 2 years ago
2 0 2 years ago

I've become interested in SBOM recently, and found there were great tools like https://dependencytrack.org/ for CycloneDX SBOMs, but all I have is SPDX SBOMs generated by GitHub.

I decided to have a go at writing my own dependency track esque tool aiming to integrate with the APIs GitHub provides.

It's pretty limited in functionality so far, but can give a high level summary of the types of licenses your repository dependencies use, and let you drill down into potentially problematic ones.

Written in NextJS + mui + sqlite, and using another project of mine to generate most of the API boilerplate/glue (https://github.com/mnahkies/openapi-code-generator)

Related Stories

Loading related stories...

Source preview

github.com