OWASP depscan is an open-source security audit based on known vulnerabilities and advisories for project dependencies. Supports both local repos and container images. Integrates with various CI environments such as GitHub Action, Azure Pipelines, CircleCI, Jenkins, and Google CloudBuild.
OWASP CycloneDX Generator
cdxgen is a cli tool, library, REPL, and server to create a valid and compliant CycloneDX Software Bill-of-Materials (SBOM) containing an aggregate of all project dependencies for c/c++, node.js, php, python, ruby, rust, java, .Net, dart, haskell, elixir, and Go projects in JSON format.