Syft


Syft

License: Apache-2.0 license


Description:

Syft is a CLI tool and library for generating SBOMs from container images, filesystems, and other artifacts; exports to SPDX/CycloneDX formats and integrates with Grype for vulnerability scanning.

Grype


Grype

License: Apache-2.0 license


Description:

A vulnerability scanner for container images and filesystems; scans SBOMs and images to identify known vulnerabilities, integrates with Syft and OpenVEX for composable, auditable results.

SpiderFoot


SpiderFoot

License: MIT license


Description:

SpiderFoot is an open source intelligence (OSINT) automation tool. It integrates with just about every data source available and utilises a range of methods for data analysis, making that data easy to navigate.

SpiderFoot has an embedded web-server for providing a clean and intuitive web-based interface but can also be used completely via the command-line. It’s written in Python 3 and MIT-licensed.

OpenZL

OpenZL

License: BSD license


Description:

OpenZL is a framework for building format-aware data compressors. It generates specialized compressors from data descriptions, all compatible with a single universal decompressor, delivering high compression and speed for large-scale data workflows.