trailofbits/it-depends
A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.
PythonLGPL-3.0
Issues
- 0
- 0
setuptools is a required dependency
#86 opened by cpswan - 0
Please consider adopting OpenSSF Scorecard
#85 opened by andrewpollock - 1
Error: "Can not resolve . "
#81 opened by Mhbuur - 1
- 1
it-depends does not find Docker on Mac
#82 opened by kedhammar - 6
Document the platforms supported
#60 opened by mike-myers-tob - 0
Error on npm project
#78 opened by cosad3s - 0
FileNotFoundError: [Errno 2] No such file or directory: '/tmp/tmpy99_9n56/output'
#76 opened by nanHeK - 2
- 1
- 0
Docker support broken for podman users
#63 opened by nathantypanski - 1
- 2
Version string lacks a numerical component
#65 opened by timjrobinson - 0
No dependencies for a CMake project
#66 opened by ja-he - 0
NPM dependency resolution is not accurate
#62 opened by sambacha - 2
Map packages against Google OSV
#56 opened by ESultanik - 0
Non-existing package causes traceback
#57 opened by hbrodin - 1
Updates in ubuntu db will break CI
#44 opened by feliam - 0
- 0
Optional max depth for dependency resolution
#16 opened by ESultanik - 0
Move all our shell needs to a container
#30 opened by feliam - 0
Initial means for comparing dependency trees
#20 opened by ESultanik - 0
Be less strict about project name in CMake
#32 opened by feliam - 2
- 1
- 1
- 1
Support for output in ~CycloneDX~ SPDX
#36 opened by ESultanik - 1
Examples of each type of project supported
#14 opened by ESultanik - 0
Support for Go
#17 opened by ESultanik - 1
Documentation
#12 opened by ESultanik - 0
Autotool ignores Boost dependencies
#29 opened by feliam - 0
- 1
Match against `cvedb` for packages
#18 opened by ESultanik - 0
- 0
Set up PyPI repository secrets
#13 opened by ESultanik