spdx / outreach

content for outreach activities
5 stars 10 forks source link

[Tool Request]: dependency-management-data #75

Closed jamietanna closed 3 months ago

jamietanna commented 4 months ago

Tool or Product name

dependency-management-data

Open Source or Proprietary

open source

Company or Organization name

No company

Organization or Company Logo Usage

Public Contact Email or URL

https;//dmd.tanna.dev

Product or tool website

https;//dmd.tanna.dev

Description

Dependency Management Data (DMD) is a set of tooling to get a better understanding of the use of dependencies across your organisation.

The project consumes various formats (including SPDX SBOMs) and can then provide insight into use of deprecated, unmaintained or insecure packages, as well as providing a queryable interface (using SQL or GraphQL, so you can target changes across your projects and organisation more appropriately.

SBOM tool category

SPDX Versions supported

SPDX verification

https://dmd.tanna.dev/cookbooks/getting-started-sbom/ + we use the official library

How to procure

Build from source:

go install dmd.tanna.dev/cmd/dmd@latest

Or use pre-built binaries:

https://gitlab.com/tanna.dev/dependency-management-data/-/releases/

Installation instructions

dmd db init --db /path/to/output.db
dmd import sbom --db /path/to/output.db ...

Link to quick start guide

https://dmd.tanna.dev/cookbooks/getting-started-sbom/

podence commented 3 months ago

Added to new page to be deployed.