Skip to content

yadhukrishnam/supplyshield

 
 

Repository files navigation

SupplyShield

SupplyShield is an application security orchestration tool for DevSecOps requirements.

Python 3.10+ stability-wip

SupplyShield leverages primarily the following tools:

  1. cdxgen: For generating codebase SBOM
  2. osv: SCA database for cdxgen
  3. syft: For generating docker container SBOM
  4. grype: For generating docker container SCA
  5. ScancodeIO: Pipeline for SupplyShield scans
  6. Semgrep: SAST Engine

SupplyShield is under active development, releases are available under the "releases" section on GitHub.

Read more about SupplyShield at [docs](./docs/_build/html)

SupplyShield tech stack is Python, Flask, PostgreSQL and Docker and several libraries.

Copyright notice

Copyright (c) SupplyShield and others. All rights reserved.

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Python 80.8%
  • HTML 17.1%
  • Makefile 1.5%
  • Other 0.6%