Skip to content

Commit 1b8b7e6

Browse files
committed
Add FOSSA to the SBOM catalog
1 parent f9cf804 commit 1b8b7e6

File tree

3 files changed

+76
-0
lines changed

3 files changed

+76
-0
lines changed

SBOM-Catalog/public/data.yaml

+71
Original file line numberDiff line numberDiff line change
@@ -6904,3 +6904,74 @@
69046904
SBOM data interpretation and supply chain transparency.'
69056905
Types:
69066906
- Analyze
6907+
- Abilities:
6908+
- Consume
6909+
- Convert
6910+
- Edit
6911+
- Generate
6912+
- Validate
6913+
Languages:
6914+
- Clojure
6915+
- C
6916+
- "C++"
6917+
- Dart
6918+
- Dotnet
6919+
- Erlang
6920+
- Elixir
6921+
- Fortran
6922+
- Go
6923+
- Haskell
6924+
- Java
6925+
- Javascript
6926+
- Nim
6927+
- "Objective-C"
6928+
- Perl
6929+
- PHP
6930+
- Python
6931+
- R
6932+
- Ruby
6933+
- Rust
6934+
- Scala
6935+
- Swift
6936+
- Typescript
6937+
License: Proprietary
6938+
Link: https://fossa.com
6939+
Name: FOSSA
6940+
Publisher: FOSSA
6941+
Source: Human reviewed
6942+
Standards:
6943+
- SPDX
6944+
- CycloneDX
6945+
Summary: 'FOSSA is a software composition analysis (SCA) tool with robust SBOM management capabilities.
6946+
It empowers you to generate detailed, precise reports of all code dependencies for any version of your software, regardless of depth.
6947+
Additionally, FOSSA allows you to import external SBOMs, consolidating third-party license and security risks into a single, unified view.
6948+
With the flexibility to export SBOMs in multiple formats such as CycloneDX and SPDX, you can either download and distribute them yourself
6949+
or let FOSSA host them on your behalf. Moreover, its auto-update feature ensures that all SBOMs remain current, centralizing the management
6950+
of both internal and third-party components for seamless compliance and risk control.
6951+
6952+
6953+
Key Features:
6954+
6955+
- Supports CycloneDX and SPDX
6956+
6957+
- Exceeds U.S. government minimum SBOM requirements
6958+
6959+
- Utilizes multiple analysis techniques to produce an audit-grade component inventory
6960+
6961+
- Integrates locally or with version control systems
6962+
6963+
- Offers a powerful FOSSA CLI with comprehensive support for many languages and package managers, licensed under CPAL-1.0
6964+
6965+
- Generates SBOMs for any prior version of your software
6966+
6967+
- Can be customized for a range of security, regulatory compliance, and license compliance use cases
6968+
6969+
- Does not require source code access
6970+
6971+
6972+
This comprehensive approach enables seamless compliance and risk management across your software ecosystem.'
6973+
Types:
6974+
- Analyzed
6975+
- Build
6976+
- Deployed
6977+
- Source
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
[FOSSA](https://fossa.com) is a software composition analysis tool with a mature SBOM management product offering. The SBOM management tool enables users to produce and ingest SBOMs in either SPDX or CycloneDX, monitor SBOMs for vulnerabilities and license compliance issues, and securely share SBOMs with customers. FOSSA also offers extensive remediation support to help organizations prioritize vulnerabilities they may uncover associated with the components in their SBOM.
2+
3+
For more information about SBOM Management in FOSSA, please watch FOSSA's YouTube playlist [here](https://www.youtube.com/watch?v=H3UqVumgUFQ&list=PLDgTaRwpXLSeERefRakUujZveG47U3uCr).
4+
Also, explore FOSSA's SBOM documentation [here](https://docs.fossa.com/docs/using-fossa-sbom-management).
5+
For more details about the FOSSA CLI, you can explore the GitHub repository [here](https://github.com/fossas/fossa-cli).

SBOM-Catalog/public/logos/FOSSA.png

7.44 KB
Loading

0 commit comments

Comments
 (0)