A Go-based CLI tool to automate the upload and lifecycle management of Software Bill of Materials (SBOM) in OWASP Dependency-Track.
-
Updated
Jan 24, 2026 - Go
A Go-based CLI tool to automate the upload and lifecycle management of Software Bill of Materials (SBOM) in OWASP Dependency-Track.
"This is a simulated DevSecOps pipeline demo using a vulnerable Flask app, integrated with GitHub Actions CI and security tools like Bandit and Semgrep. It simulates how real companies automate vulnerability scanning in CI/CD."
Add a description, image, and links to the devsecops-coe-managed topic page so that developers can more easily learn about it.
To associate your repository with the devsecops-coe-managed topic, visit your repo's landing page and select "manage topics."