Open
Description
User story
As a lazy open source referent
I want to launch in one command an audit of a repository to clone
so that I can check quickly if there are some third-party components
and in the end generate the SBOM and the THIRD-PARTYY
Details
- See scancode-toolkit
- See this tool
- See spdx-sbom-generator
- See CycloneDX
- See Syft
- See fossa