BigHugger
sk Skill · mukul975

generating-and-analyzing-sboms

Generate CycloneDX and SPDX SBOMs from container images and filesystems with Syft, correlate them to CVEs with Grype, and sign/attest them with Cosign. Use when you need a machine-readable dependency inventory for supply-chain risk, want to scan images or SBOMs for known vulnerabilities, or are embedding SBOM generation and vulnerability gating into CI/CD.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythondevsecopssyftbashvulnerability-managementspdxcyclonedxsbomgrypesupply-chain-security
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python