spdx / outreach

content for outreach activities
4 stars 9 forks source link

[Tool Request]: GUAC #64

Closed funnelfiasco closed 1 month ago

funnelfiasco commented 3 months ago

Tool or Product name

GUAC (Graph for Understanding Artifact Composition)

Open Source or Proprietary

open source

Company or Organization name

OpenSSF

Organization or Company Logo Usage

Public Contact Email or URL

https://guac.sh/

Product or tool website

https://guac.sh/

Description

GUAC aggregates software security metadata into a high fidelity graph database—normalizing entity identities and mapping standard relationships between them. Querying this graph can drive higher-level organizational outcomes such as audit, policy, risk management, and even developer assistance.

SBOM tool category

SPDX Versions supported

SPDX verification

GUAC uses the SPDX Golang tooling

How to procure

Download binaries or build from source.

Installation instructions

https://docs.guac.sh/getting-started/

Link to quick start guide

https://docs.guac.sh/getting-started/

mlieberman85 commented 3 months ago

Ping @goneall

goneall commented 3 months ago

We're in the middle of creating a new web page for the tools - should be available around mid June.

If you're OK waiting until then, we'll include Guac - it is definitely a tool I'd like to add to the website

funnelfiasco commented 3 months ago

@goneall I think we can wait a few weeks. Thanks for the update!

goneall commented 2 months ago

It's taking longer than expected to get the new tools web pages in shape, so I went ahead and added GUAC to the existing page.

Let's leave this issue open to track adding it to the new format.

Let me know if you see any issues with the updated information.

funnelfiasco commented 2 months ago

Looks good to me! Thanks for following up on this

podence commented 1 month ago

Added to new page to be deployed.