The Wayback Machine - https://web.archive.org/web/20201105085848/https://github.com/stevespringett
Skip to content
Avatar

Highlights

  • Arctic Code Vault Contributor
  • Pro

Organizations

@jenkinsci @maintainers @CycloneDX @package-url @DependencyTrack @ossf

Pinned

  1. Dependency-Track is an intelligent Supply Chain Component Analysis platform that allows organizations to identify and reduce risk from the use of third-party and open source components.

    Java 624 196

  2. Software Bill-of-Material (SBOM) specification designed for use in application security contexts and supply chain component analysis

    XSLT 42 10

  3. A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby

    139 35

  4. Software Component Verification Standard (SCVS)

    Python 51 8

  5. A utility for validating and parsing Common Platform Enumeration (CPE) v2.2 and v2.3 as originally defined by MITRE and maintained by NIST

    Java 19 7

  6. A Java library for calculating CVSSv2 and CVSSv3 scores and vectors

    Java 17 10

1,766 contributions in the last year

Nov Dec Jan Feb Mar Apr May Jun Jul Aug Sep Oct Mon Wed Fri

Contribution activity

November 2020

Created an issue in CycloneDX/cyclonedx-cli that received 1 comment

Define support for CycloneDX 1.1

When converting CycloneDX 1.1 XML to SPDX, I receive the following error: Unhandled exception: System.InvalidOperationException: There is an error …

1 comment
Opened 2 other issues in 2 repositories
CycloneDX/cyclonedx-cli
1 open
CycloneDX/specification
1 open
You can’t perform that action at this time.