Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add GUAC to the catalog #62

Merged
merged 1 commit into from
Jul 11, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions SBOM-Catalog/public/data.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -578,3 +578,19 @@
- Validate
Type:
Language:

- Name: GUAC
Link: https://github.com/guacsec/guac
Publisher: GUAC (OpenSSF)
License: OpenSource
Standards:
- CycloneDX
- SPDX
Abilities:
- Consume
funnelfiasco marked this conversation as resolved.
Show resolved Hide resolved
Type:
- Source
- Build
- Analyzed
Language:
- Generic
12 changes: 12 additions & 0 deletions SBOM-Catalog/public/descriptions/GUAC.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
[Graph for Understanding Artifact Composition](https://guac.sh) (GUAC) provides supply chain observability with a graph view of the software supply chain and tools for performing queries to gain actionable insights.

GUAC is for developers, operations, and security practitioners who need to identify and address problems in their software supply chain, including proactively managing dependencies and responding to vulnerabilities.

GUAC has three key differentiating features from other tools in this space

* **Works on more than one SBOM at a time.**
This allows observability into the entire software portfolio instead of application-by-application.
* **Aggregates additional data beyond the SBOM.**
GUAC brings in data like dependencies and vulnerabilities from trusted third-party sources, enriching the supply chain graph.
* **Provides APIs and a visualization tool.**
GUAC’s query and visualization tooling let the user get the answers to the questions they need to ask.
Binary file added SBOM-Catalog/public/logos/GUAC.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading