
SBOMHub
Track vulnerabilities across all your software projects
What it does
SBOMHub is an open-source dashboard that helps you manage Software Bill of Materials (SBOMs) and track vulnerabilities across all your projects. Import SBOMs from Syft, Trivy, or cdxgen. Get matched against NVD vulnerabilities. Prioritize by EPSS scores. Search CVEs across all projects instantly. Free tier available. Self-host option with AGPL-3.0 license.
Does a similar job
all alternatives →
- SSSocket – Secure your JavaScript supply chain2022 · socket.dev · ▲133
Excited to share the project I've been working on for the past 7 months! We've seen nearly weekly attacks against the open source software supply chain. I saw the seeds of this trend start in the mid 2015s as an open source maintainer and I've watched it only get worse over the years. I finally decided to try to solve this problem. Socket is taking an entirely new approach to one of the hardest problems in security in a stagnant part of the industry that has historically been obsessed with just reporting on known vulnerabilities. Unlike other scanning tools, Socket actually analyzes the…

- SZSecureBuild – Zero-CVE Images That Pay OSS Projects2025 · securebuild.com · ▲40
We're launching SecureBuild: https://securebuild.com — a new way for open source projects and maintainers to earn revenue by partnering with and endorsing our Zero-CVE container images of their project. We’ve spent the last decade at Replicated (https://news.ycombinator.com/item?id=9841243) helping commercial and open source software vendors securely distribute their apps to enterprise environments. During that time, we saw firsthand how hard it is for maintainers to fund their work, and how increasingly demanding enterprises have become when it comes to demonstrable…
Osint tool that finds exposed files on domainsJul 2026 · search.cerast-intelligence.com · ▲58hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…
DepticJun 2026 · deptic.netlify.app · ▲3Scan any GitHub repo.Generate SBOMs & detect CVEs instantly.
More dev tools this month
the category →



OpenTrailPaper is open-source bike computer firmware for the LilyGO T5S3 4.7" E-Paper PRO. It supports offline maps, GPX routes, FIT recording and Bluetooth sensors.
Dev tools · 2d ago · opentrailpaper.com

Open-source GTM skills for technical founders
Dev tools · 30d ago · gtmcofounder.com
