Skip to content
View johnmhoran's full-sized avatar

Organizations

@nexB @package-url @aboutcode-org

Block or report johnmhoran

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby

Python 909 206 Updated Nov 10, 2025

Python implementation of the package url spec. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ , the Google Summer of Code, nexB and other generous sponsors.

Python 79 51 Updated Sep 7, 2025

Parse and compare all the package versions and all the ranges. From debian, npm, pypi, ruby and more. Process all the version range specs and expressions. This project is sponsored by an NLnet proj…

Python 38 18 Updated Sep 11, 2025

A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatab…

Python 638 244 Updated Nov 6, 2025

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. …

C# 4,370 363 Updated Oct 21, 2025

OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, an…

XSLT 439 74 Updated Nov 12, 2025

Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Cha…

HTML 53 37 Updated Oct 28, 2025

ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydata…

Python 155 126 Updated Nov 11, 2025

Various data formats for the SPDX License List including RDFa, HTML, Text, and JSON

HTML 609 176 Updated Oct 28, 2025

The System Package Data Exchange (SPDX) specification in Markdown and HTML formats.

Python 345 148 Updated Nov 11, 2025

FOSSology is an open source license compliance software system and toolkit. As a toolkit you can run license, copyright and export control scans from the command line. As a system, a database and w…

HTML 918 498 Updated Nov 7, 2025

📊 ScanCode Workbench is a desktop app to review and conclude license and origin from code scans generated by ScanCode Toolkit.

TypeScript 168 78 Updated Jan 17, 2025

DeltaCode: compare two codebase scans (from ScanCode) to detect significant changes.

Python 22 27 Updated Sep 3, 2024

🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nln…

Python 2,405 618 Updated Nov 12, 2025