cbomkit/sonar-cryptography
JavaApache-2.0active
Health
This repository contains a SonarQube Plugin that detects cryptographic assets in source code and generates CBOM.
Health Breakdown
Activity25
Community25
Maintenance8
Popularity22
#cbom#cbom-tool#cbomkit#crypto-scanner#cryptographic-inventory#cryptography#cryptography-bom#post-quantum#post-quantum-cryptography#quantum-safe#sbom#sbom-tool#sonar#sonarqube
Should you contribute to cbomkit/sonar-cryptography?
cbomkit/sonar-cryptography has a FoundDev health score of 81/100, which puts it in the active-and-maintained tier. The maintainer team is shipping recently, issues are being closed, and a PR you open this week has a realistic chance of being reviewed.
Last push was 0 days ago — that signals an actively maintained project. New issues are likely to get a maintainer response within days. The project is written primarily in Java, so prior Java experience will shorten ramp-up.
Licensed under Apache-2.0, a standard OSI-approved license — safe to contribute to under normal employer IP policies.
Community
JavaApache 2.0
active
0d ago