
ReARM
Release governance platform storing per-release SBOMs, scan results, signatures, and attestations.
PlatformWebfreemiumglobal

ReARM is an open-source Release Governance Platform that centrally stores per-release SBOMs, scan results, signatures, and attestations to answer supply-chain compliance questions like where a given CVE is shipping across an organization's whole portfolio. It integrates with Dependency-Track for vulnerability analysis and major CI systems for automated BOM generation. It's aimed at engineering and compliance teams who need to track SBOMs and vulnerabilities across their software portfolio for regulations like the EU CRA.
Categories
software supply chain securityrelease managementcompliance
Something wrong with this listing — dead link, not a real product, wrong info?

