@nexB
  • Stars
    star
    637
  • Global Org. Rank 20,586 (Top 7 %)
  • Registered almost 10 years ago
  • Most used languages
    Python
    76.6 %
    HTML
    10.6 %
    C
    2.1 %
    Batchfile
    2.1 %
    C#
    2.1 %
    Go
    2.1 %
    Makefile
    2.1 %
    TypeScript
    2.1 %
  • Location 🇺🇸 United States
  • Country Total Rank 3,406
  • Country Ranking
    Batchfile
    38
    Makefile
    388
    Python
    499
    TypeScript
    2,119
    HTML
    3,064

Top repositories

1

scancode-toolkit

🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase, the Google Summer of Code, Azure credits, nexB and others generous sponsors!
Python
2,033
star
2

vulnerablecode

A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
Python
510
star
3

aboutcode

AboutCode project: tools and data to uncover things about code: the provenance, origin, license, and more (packages, security, quality, etc.) of FOSS code
Batchfile
153
star
4

scancode-workbench

📊 ScanCode Workbench is a desktop app to review and conclude license and origin from code scans generated by ScanCode Toolkit.
TypeScript
145
star
5

scancode.io

ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ Google Summer of Code, nexB and others generous sponsors!
Python
94
star
6

aboutcode-toolkit

✅ AboutCode Toolkit provides a simple way to document provenance metadata (origin and license) about third-party code that you use in your project: it includes utilities to generate inventory/BOM or Attribution documentation.
Python
90
star
7

license-expression

Utility library to parse, normalize and compare License expressions for Python using a boolean logic engine. For expressions using SPDX or any other license id scheme.
Python
54
star
8

extractcode

A mostly universal file extraction library and CLI tool to extract almost any archive in a reasonably safe way on Linux, macOS and Windows.
Python
31
star
9

container-inspector

container-inspector is a suite of analysis utilities and command line tools for Docker container images, their layers and how these relate to each other. It can also handle OCI images and Dockerfiles.
Python
30
star
10

python-publicsuffix2

A small Python library to deal with publicsuffix data (includes a bundled PSL as "package data") in a wheel friendly format. Fork and continuation of Tomaž Šolc's "publicsuffix"
Python
29
star
11

purldb

Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Chat is at https://gitter.im/aboutcode-org/discuss
HTML
29
star
12

scancode-licensedb

A free and open database of all the licenses, in particular all the open source software licenses
Makefile
27
star
13

univers

Parse and compare all the package versions and all the ranges. From debian, npm, pypi, ruby and more. Process all the version range specs and expressions. This project is sponsored by an NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ , the Google Summer of Code, nexB and others generous sponsors!
Python
27
star
14

tracecode-toolkit-strace

Trace software components, packages and files between Development/Source and Deployment/Distribution/Binaries codebases - strace build analysis
Python
25
star
15

python-inspector

Inspect Python code and PyPI package manifests. Resolve Python dependencies.
Python
20
star
16

deltacode

DeltaCode: compare two codebase scans (from ScanCode) to detect significant changes.
Python
19
star
17

scancode-server

This project is no longer maintained. Visit https://github.com/nexB/scancode.io/ instead for similar and current project
Python
19
star
18

dejacode

Automate open source license compliance and ensure software supply chain integrity
Python
18
star
19

pip-requirements-parser

a mostly correct pip requirements parsing library
Python
16
star
20

debian-inspector

A python library to parse Debian deb822-style control and copyright files and all related Debian, Ubuntu and Debian-derivative manifest and metadata files, an alternative approach to python-debian.
Python
13
star
21

cwe2

Common weakness enumeration library for Python (maintained fork of https://github.com/Julian-Nash/cwe )
Python
11
star
22

saneyaml

Cleaner, simpler, safer and saner YAML parsing/serialization in Python, for YAML meant to be readable first, on top of PyYAML
Python
9
star
23

fetchcode

A library to reliably fetch code via HTTP, FTP and version control systems. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ Google Summer of Code, nexB and others generous sponsors!
HTML
9
star
24

skeleton

Python
8
star
25

typecode

Python
7
star
26

clearcode-toolkit

ClearCode is a simple tool to fetch and sync all ClearlyDefined data locally.
Python
7
star
27

scancode-analyzer

scancode-results-analyzer
Python
4
star
28

scancode-thirdparty-src

Source code for ScanCode prebuilt dependencies
HTML
4
star
29

nuget-inspector

Inspect and resolve .NET and NuGet package dependencies like dotnet and nuget do. Fetch manifests data. Runs on Linux, Windows and macOS as a standalone application.
C#
4
star
30

purldb-data

A dataset of purl for offline lookup and verification usage. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Chat is at https://gitter.im/aboutcode-org/discuss
4
star
31

scancode-action

Run ScanCode.io pipelines from your Workflows
4
star
32

commoncode

Python
3
star
33

pkginfo2

Git mirror of http://bazaar.launchpad.net/~tseaver/pkginfo ... with modifications
Python
3
star
34

pygmars

Craft simple regex-based small language lexers and parsers. Build parsers from grammars and accept Pygments lexers as an input. Derived from NLTK.
Python
3
star
35

turbo-spdx

Fast and lightweight Python library for parsing and writing SPDX JSON documents correctly.
Python
2
star
36

scancode-plugins

A set of plugins either delivered as builtin scancode-toolkit or extra plugins
HTML
2
star
37

scancode-toolkit-contrib

Candidate additions and contribution for the ScanCode toolkit
C
2
star
38

dependency-inspector

A general purpose, mostly universal software package dependency resolver.
Go
2
star
39

scancode-toolkit-plugin-cookiecutter

Python
1
star
40

plugincode

Python
1
star
41

jvm-inspector

[WIP] jvm-inspector is a set of tools and utility functions to inspect JVM byte code and source code
Python
1
star
42

sanexml

Python
1
star
43

federatedcode

Python
1
star
44

dejacode-toolkit

[Work in progress] An API client and toolkit with libraries, utilities and helpers to work with the DejaCode API
1
star
45

go-inspector

[WIP] An inspector for Go language-based source, binaries, packages, dependencies and metadata
Python
1
star
46

scancode.io-pipeline-glc_scan

Python
1
star
47

scancode-toolkit-reference-scans

scancode-toolkit-reference-scans
HTML
1
star
48

heritedcode

A software heritage API client
Python
1
star
49

vulnerablecode-data

1
star
50

aboutcode-cyclonedx-taxonomy

AboutCode CycloneDX Property Taxonomy
1
star
51

spdx-licenses

A mirror of http://spdx.org licenses
1
star
52

matchcode-toolkit

Python
1
star
53

attributecode

[Archived] This project was an Attribution generation tool with many content and format options for the input data. All its features have been folded back in the latest AboutCode Toolkit at https://github.com/nexB/aboutcode-toolkit
Python
1
star