* [Chainloop v1.107.0](https://github.com/chainloop-dev/chainloop) – Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports. * [cyclonedx-go v0.12.0](https://github.com/CycloneDX/cyclonedx-go) – Go library for producing and consuming Software Bill of Materials (SBOM) documents. * [cyclonedx-gomod v1.12.0](https://github.com/CycloneDX/cyclonedx-gomod) – Generates CycloneDX SBOMs from Go modules. * [sbomqs v2.0.12](https://github.com/interlynk-io/sbomqs) – Evaluates SBOM quality, validates compliance against standards, analyzes components, and identifies vulnerabilities. * [sbom-operator 0.44.5](https://github.com/ckotzbauer/sbom-operator) – Catalog all Kubernetes cluster container images and generate SBOMs with Syft, storing results to Git, Dependency-Track, OCI registries, or ConfigMaps. * [Konflux-CI v0.2.2-rc.14](https://github.com/konflux-ci/konflux-ci) – CI/CD platform for building, testing, and releasing applications on Kubernetes clusters.