Ecosyste.ms: OpenCollective
An open API service for software projects hosted on Open Collective.
github.com/devops-kung-fu/bomber
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
https://github.com/devops-kung-fu/bomber
79b5dc75344e146541776b3ab80c2913b75115ec authored 11 months ago
* configuration of nerdfont in devcontainer
bd9d2b848c0d389a42e9211186ef0fed83ec411e authored 11 months agoCo-authored-by: DJ Schleen <[email protected]>
6a46058d4756f51590214986dffedcc47b52d058 authored 11 months agoSigned-off-by: DJ Schleen <[email protected]>
3e05144b9dcd1b2069f231f4c7f39c5e271b8b58 authored 11 months agoSigned-off-by: DJ Schleen <[email protected]>
817ffb646beca04701faa15c39b9bf4ec3711b28 authored 11 months agoSigned-off-by: DJ Schleen <[email protected]>
0c606ffa2d8afb27f52d49f2bb3e62fb5e2065b3 authored 11 months agoSigned-off-by: DJ Schleen <[email protected]>
249f16f8668f2c51ab55714e5ac2e8cee7dd85bf authored 11 months agoSigned-off-by: DJ Schleen <[email protected]>
dfaf0f15f9a5a60c80ca3d50ec0208886fa768ba authored 11 months ago7438ff58f73e5fada999ae0e37401c6b89727fdf authored 11 months ago
* Initial commit of AI rendering scaffold
* Fixes test cases and ignore loading functionality
...
Bumps [actions/checkout](https://github.com/actions/checkout) from 3 to 4.
- [Release notes](ht...
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 4 to 5.
- [Release notes](ht...
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2 to 3.
- [Release n...
Bumps [github.com/jedib0t/go-pretty/v6](https://github.com/jedib0t/go-pretty) from 6.4.9 to 6.5....
8c44fb063c7c70fd4143536e7c1851b202305e2b authored 11 months agoSigned-off-by: DJ Schleen <[email protected]>
cb9f644e4e256374b674705a18fddbcd5a5e98e0 authored 11 months agoSigned-off-by: Pablo Hinojosa <[email protected]>
259c8b3c71da55a04bbe31e8eb39420d646d663b authored about 1 year ago
* Refactored logic out of scan.go into a scanner
* Reduced cyclomatic complexity
* More test c...
* Fixes an issue where return code was 10 if no severity flag was set
* Adds exit code function...
Version bump
0d0b5615c3f1c3ece88702772a7b827c95822b74 authored about 1 year ago
* Updates dependencies
* Flags added, return codes on os.Exit
* Filtering done implemented
* ...
* Fitering of bad purls
* Adds issue output for invalid Purls detected in SBOMS
* Simplifies j...
This adds newly supported purl types apk, deb, docker and rpm to the documentation for the Snyk ...
e8477955bdb6015bacdb8a6ea831374f2b91972c authored almost 2 years ago
* Sets CGO_ENABLED=0
* Corrects xml output label to json
* More demo sboms
---------
Co-...
c67aa58455551b0ad693066572779074bba87309 authored almost 2 years ago
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 3 to 4.
- [Release notes](ht...
3a1e17344ed67324438210d8d2ef895fae6645fb authored almost 2 years ago
315e647bec9f463f3a4854732f3dce8cf5ffc642 authored almost 2 years ago
Goreleaser not working, removed deprecated --rm-dist in favor of --clean
312dc361c857bb00089caac54615d69c90af3a79 authored almost 2 years ago75cc9d1102d70bfcae3780e6222ca73b3fe741c6 authored almost 2 years ago
Updates goreleaser to 4.2.0
808b70b2040f259ddd36df21e31984b1f18a68ce authored almost 2 years agodf459ace6caeea0f00b8e86915c9f36907f89d93 authored almost 2 years ago
* Doesn't process components without purls (or empty purl nodes)
* Syft action in release.yml f...
5c7e7dd1653f2290fe23133ac8d63494e8cd8ae3 authored almost 2 years ago
64ab76a1613a3d14f44443b8a5b4da8376976d55 authored almost 2 years ago
chore: update snyk readme to include mor ecosystems support
fcea0a1b2ab81478735e2d3b83818cbacf44ef33 authored almost 2 years agoAdds sponsor link
7e83fd21f25cdb4e5d45940a3299e1edeb6cac00 authored about 2 years ago44323cccd75527397103201bdc3ef238527fae4a authored about 2 years ago
82dc67e2f0069d9deb06b0bde3aa896ec6a8116e authored about 2 years ago
df79c72d2317944fa9eedcce843927a596e70be7 authored about 2 years ago
2a2695b481122eaf6c9e90773c9886c171428100 authored about 2 years ago
* Fixes issue where a license expression wasn't being utilized
* Improves test coverage
1a421ad919879a1fb902bfb00089d9d89285f91c authored about 2 years ago
* EPSS enrichment feeds off Vulnerability.Cve
* Adds Cve field to osv vulnerability output
* F...
build(deps): bump goreleaser/goreleaser-action in /.github/workflows
Bumps [goreleaser/gorele...
c8a0f6be4280fab120bee2586858361460586c0e authored about 2 years agoBumps [github.com/jedib0t/go-pretty/v6](https://github.com/jedib0t/go-pretty) from 6.4.2 to 6.4....
ef3d15f973057753d738e912c7b0aa37fa9db59a authored about 2 years ago
Bumps [github.com/stretchr/testify](https://github.com/stretchr/testify) from 1.8.0 to 1.8.1.
-...
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 2 to 3.
- [Release notes](ht...
* Adds Snyk provider documentation
d1c36c6bbdd07a6842ba61cc06a83440ca5b7df9 authored about 2 years ago
* Updated documentation for EPSS
* STDOUT now renders EPSS percentage
* Centralization of enri...
The links to the download locations are leading to hookz project releases and not Bomber.
ed7b8f0670e4b7d34d93deafa6b256292f28a7dd authored about 2 years ago86ed119b63f1b69608243d22a8792eb84229d603 authored about 2 years ago
* Adds section in JSON for scanned files with sha256 hash
* Adds file section with names and ha...
Pass package URL when querying OSV
Co-authored-by: DJ Schleen <[email protected]>
ec11bf6c49bba28830f3867f91594cf7cc39bdd9 authored about 2 years agoDeletes extra characters from HTML template
f1306a54a9fa0e3ea47f93b0f76a95d046fdd3a5 authored about 2 years agoComplexity fix for STDIN changes
459a9c3723eb3af6970599be41f79f315e591af1 authored over 2 years ago
Explicit rather than implicit. Use "-" as an argument to scan to trigger
reading from stdin.
* Renders and sanitizes Markdown vuln descriptions to HTML
* Adds error check for res close i...
7e1a7239c18dcc7795c436541ef8d9c4db471832 authored over 2 years ago
Co-authored-by: Maximilian Combüchen <[email protected]>
Co-authored-by: Gareth Rushgrove <...
bd5178f299956e6eaf7ad8581469581def05f404 authored over 2 years ago
Test file clutter
697f08b9b381d12017b6d99bb74916db53f17af0 authored over 2 years ago* License support for STDOUT
* Adds Licenses to html renderer, fixes rendering when no vulns ...
d58403ddf6851bec5742daca5c8fbfcecc951a0d authored over 2 years ago
* Adds xml format support for CycloneDX
* Version bump
8be71528b9b892de334c66369f13213b8cc33cce authored over 2 years ago
* Initial html output
* Fixes strange severity issues, colors severity output in html, update...
d9898cd3d00b7ab67c3b1658b79671b9945e39a4 authored over 2 years ago* Refactored rendering logic out of cmd
* Fixes issue where SPDX wasn't being recognized
*...
93dd74fdc6de980667b07f11050f027e1b1f8636 authored over 2 years ago* Removed removeDuplicates in favor of DKFM common
b32963ea1f18d65f095370143a5e64d633ac825b authored over 2 years ago
* Provider factory
* http request cleanup
* Removes README.md reference to bomber being a modu...
Fixes strange merge problems
3cfed2bddd10e3b102b276ceb1508c0a82616e6f authored over 2 years ago
* Initial output of JSON
* Fixes OSV output not showing
* Omits empty fields in json output
*...
* JSON output using --output
* Fixes OSV output not showing
* Omits empty fields in json outpu...
Fixes severity to use Moderate instead of Medium
275a85efda8c2a9f1494be8d7a87228bffd5c45c authored over 2 years agoAdds ecosystem pre-scan info
92636f920a69e8482d8be1192968e886560f71ce authored over 2 years agoFixes updated README.md
697ad6dae951825b777564c174f3dc020cae6f24 authored over 2 years agoFixes release typo from hookz to bomber
537b4e988d98abed10dc510f2eb079a440e30a7b authored over 2 years ago
* Extracting common interface, stub out OSV provider
* Initial Snyk providers
* Implemented OS...
* Adds vulnerability struct for OSSIndex vuln details
* Adds debug and enhanced summary output
...
Warns on missing credentials, fixes output when no valid SBOMs are found
a4c228ea261be1680c505673729140076cb7b629 authored over 2 years agoFixes bomber's sbom badge links
c6b6cddefb3cafbb90b80dba350d97e77d913933 authored over 2 years agoUpdate README.md
Fixes codecov badge
d512cb911d1e4ca594f38c4bdb95715737c50d6e authored over 2 years ago
* Adding cli
* Tabular output
* Working functionality for scanning against OSSIndex
* Impleme...
* Initial repository structure and structs
* Adds github release workflow
* Stubs out tests
*...
a60511eb042017fb13cd96ada7cd647751200f35 authored over 2 years ago