retire
Retire is a tool for detecting use of vulnerable libraries
Found 8 results for software-composition-analysis
Retire is a tool for detecting use of vulnerable libraries
Automated SBOM generation and vulnerability scanning for multiple repositories. Generates CycloneDX SBOMs, scans with Trivy, and notifies via Slack/email.
A Model Context Protocol (MCP) server for Blackduck and Server APIs, built with Node.js. Provides comprehensive tools for listing BOM, Operational risks and security issues
Model Context Protocol (MCP) server for Black Duck SCA — vulnerability scanning, remediation, and PR automation for AI assistants
Stop npm supply-chain attacks before they execute. Zero-dependency security scanner: malicious package detection, lockfile audit, dropper detection, integrity checks, OWASP A03/A05/A08/A10 coverage, CycloneDX SBOM & VEX reports, provenance verification, s
Feature-rich MCP server for Black Duck Polaris — trigger SAST/SCA/DAST scans, query findings, generate reports (SBOM, SPDX, CycloneDX), manage policies, triage issues, and more. Works with Claude Code, Claude Desktop, GitHub Copilot, Cursor, and any MCP-c
TypeScript client for the Black Duck REST API
Official CLI tool for the SentraSec Platform - Performs Software Composition Analysis (SCA) scans