diff --git a/sbom.md b/sbom.md index 67401dc..daaffe4 100644 --- a/sbom.md +++ b/sbom.md @@ -49,12 +49,32 @@ ## Market Overview -Most used list: https://spdx.dev/use/spdx-tools/ +Most used from this list: https://spdx.dev/use/spdx-tools/ -| Name and Link | Key Features | Licenses | Approx Costs | -| ------------- | ------------ | -------- | ------------ | +| Name and Link | Key Features | License | Approx Costs | +| ------------- | ------------ | ------- | ------------ | | [Microsofts SBOM Tool](https://github.com/microsoft/sbom-tool) | `tbd` | MIT | Open Source | | [Syft](https://github.com/anchore/syft) | `tbd` | Apache-2.0 | Open Source | | [ScanCode toolkit](https://github.com/aboutcode-org/scancode-toolkit) | `tbd` | Apache-2.0 | Open Source | | [SCANOSS](https://www.scanoss.com) | `tbd` | Proprietary | Free, 35K per Year, Custom | -| [Vigilant Ops](https://www.vigilant-ops.com)| `tbd` | Proprietary | Unknown | +| [Vigilant Ops](https://www.vigilant-ops.com) | `tbd` | Proprietary | Unknown | +| [Threatrix](https://threatrix.io) | `tbd` | Proprietary | Unknown | +| [Black Duck](https://www.blackduck.com) | `tbd` | Proprietary | Unknown | +| [OSS Review Toolkit](https://oss-review-toolkit.org) | `tbd` | Apache-2.0 | Open Source | +| [Manifest](https://www.manifestcyber.com) | `tbd` | Proprietary | Unknown | +| [Lib4SBOM](https://github.com/anthonyharrison/lib4sbom) | `tbd` | Apache-2.0 | Open Source | +| [GUAC](https://guac.sh) | `tbd` | Apache-2.0 | Open Source | +| [FOSSology](https://www.fossology.org) | `tbd` | GPL-2.0 / LGPL-2.1 | Open Source | +| [DISTRO2SBOM](https://github.com/anthonyharrison/distro2sbom) | `tbd` | Apache-2.0 | Open Source | +| [CycloneDX](https://github.com/CycloneDX) | `tbd` | Apache-2.0 | Open Source | +| [CAST SBOM Manager](https://www.castsoftware.com/sbommanager) | `tbd` | Proprietary | Free | +| [Dependency Track](https://dependencytrack.org) | `tbd` | Apache-2.0 | Open Source | +| [Trivy](https://trivy.dev) | `tbd` | Apache-2.0 | Open Source | +| [Parlay](https://github.com/snyk/parlay) | `tbd` | Apache-2.0 | Open Source | +| [Finite State](https://finitestate.io) | `tbd` | Proprietary | Unknown | +| [Checkmarx](https://checkmarx.com/product/sbom/) | `tbd` | Proprietary | Unknown | +| [Anchore](https://anchore.com) | `tbd` | Proprietary | Unknown | +| [Qwiet](https://qwiet.ai) | `tbd` | Proprietary | Unknown | +| [Snyk](https://snyk.io) | `tbd` | Proprietary | Unknown | +| [SBOM Observer](https://sbom.observer) | `tbd` | Proprietary | 49 EUR/user/month, 69 EUR/user/month, Custom | +| [SOOS](https://soos.io) | `tbd` | Proprietary | $0/month, $90/month, Custom |