A tool for detecting cryptographic assets in container images and directories, and generating CBOMs.
-
Updated
Sep 30, 2026 - Go
A tool for detecting cryptographic assets in container images and directories, and generating CBOMs.
Cryptographic Discovery Scanner - Find every cryptographic algorithm in your codebase and know your quantum risk - part of the QRAMM Toolkit by CSNP
TLS/SSL security analyzer for quantum readiness assessment and CNSA 2.0 compliance
Cryptographic Dependency Scanner - Identify quantum-vulnerable cryptographic algorithms in your software dependencies. Part of the QRAMM Toolkit.
CLI tool to scan filesystems, containers, and network ports for cryptographic assets and generate a CycloneDX CBOM.
Post-quantum cryptography scanner: detects quantum-vulnerable algorithms across 14+ languages with CycloneDX 1.7 CBOM output and CNSA 2.0 compliance checking
Cryptography Security Graph — CBOM/PQC discovery and crypto-agility (Apache-2.0)
Repository for uploading, retrieving, and searching Cryptographic Bills of Materials (CBOM) documents.
Cryptographic asset inventory and compliance platform — discover TLS/SSH/PKI usage across your network, generate signed CycloneDX CBOMs, and track PQC readiness. Source-available (FSL-1.1-ALv2).
Map the cryptography across your live estate (TLS, SSH, X.509) and rank it against a quantum threat model. Emits a CycloneDX CBOM + SARIF. Stdlib-only Go.
Cryptographic inventory & certificate-lifecycle readiness scanner: 47-day TLS and post-quantum readiness across endpoints, Kubernetes and AWS ACM. CycloneDX CBOM + Prometheus.
Decide and sign off PQC migrations on top of what pqcota observed — reconciliation, review, finalized plans. Source-available (BUSL-1.1), becomes Apache-2.0 in 2030. | pqcota가 관측한 것 위에서 대조·리뷰·확정을 맡는 지휘봉
PQC migration for legacy crypto runtimes (OpenSSL · Java JCA): discover → inventory → provision. Observes and generates; execution stays in your hands. | 레거시 암호 런타임의 PQC 이관을 3단계로 다루는 OSS 플랫폼
Shared contracts (protobuf), generated Go code and vocabulary for pqcota, the PQC migration platform for legacy crypto runtimes.
Inventory stage of pqcota: normalizes and stores crypto observations as an append-only history with read-only views.
Post-quantum crypto readiness scanner for identity infrastructure — OIDC/JWKS, TLS, source code. CBOM output, CI gate.
Discovery stage of pqcota: collectors that observe the crypto a running system actually uses (OpenSSL, Java JCA, Windows CNG, network).
To associate your repository with the cbom topic, visit your repo's landing page and select "manage topics."