Tools
These are tools that support or use PURL or VERS.
A Ruby gem for parsing, comparing and sorting versions according to the VERS spec.
- Base language: Ruby
- Software License: MIT
- Standards: VERS
BANG is a framework for processing binary files (like firmware).
- Base language: Python
- Software License: GPL-3.0
- Standards: PURL v1.0
A software assurance platform to measure risk and detect threats in critical open-source supply chains.
- Standards: PURL v1.0
A Rust library (with WASM support) for parsing, validating, and checking version range specifiers.
- Base language: Rust
- Software License: Apache-2.0
- Standards: VERS
DefectDojo is a DevSecOps, ASPM (application security posture management), and vulnerability management tool.
- Base language: HTML
- Software License: BSD-3-Clause
- Standards: PURL v1.0
Automate open source license compliance and ensure software supply chain integrity
- Base language: Python
- Software License: AGPL-3.0-only
- Standards: PURL v1.0
Dependency-Check is a Software Composition Analysis (SCA) tool that attempts to detect publicly disclosed vulnerabilities contained within a project's dependencies.
- Base language: Java
- Software License: Apache-2.0
- Standards: PURL v1.0
Open source component analysis platform.
- Base language: Java
- Software License: Apache-2.0
- Standards: PURL v1.0
Indexes and analyzes open source packages, ecosystems, and their dependencies.
- Base language: Ruby
- Software License: AGPL-3.0-only
- Standards: PURL v1.0
Implementation of the purl (package url) specification.
- Base language: Erlang, Elixir
- Software License: Apache-2.0
- Standards: PURL v1.0
Allows third-party tools to submit dependency data to GitHub for inclusion in a repository's dependency graph.
- Standards: PURL v1.0
This package provides decoders and encoders in OCaml.
- Base language: OCaml
- Software License: ISC
- Standards: PURL v1.0
A PURL ( https://tc54.org/purl/ ) parser and serializer.
- Base language: JavaScript
- Software License: MIT
- Standards: PURL v1.0
A unifying CLI (mpm) that wraps ~30 package managers (Homebrew, apt, pip, npm, ...) behind a single interface. Accepts plain, versioned and pkg: PURL specifiers on search, install, upgrade and remove subcommands, and dispatches to the appropriate package manager based on the PURL type.
- Base language: Python
- Software License: GPL-2.0-or-later
- Standards: PURL v1.0
Java implementation of vers, a mostly universal version range specifier.
- Base language: Java
- Software License: Apache-2.0
- Standards: VERS
A suite of tools to assist with automating Open Source compliance checks.
- Base language: Kotlin
- Software License: Apache-2.0
- Standards: PURL v1.0
Open Source Vulnerability database
- Base language: Python
- Software License: Apache-2.0
- Standards: PURL v1.0
OSV-Scanner provides an officially supported frontend to the OSV database and CLI interface to OSV-Scalibr that connects a project’s list of dependencies with the vulnerabilities that affect them.
- Base language: Go
- Software License: Apache-2.0
- Standards: PURL v1.0
A PURL (Package-URL) viewer website showing registry link and content from PurlDB and VulnerableCode
- Base language: TypeScript, HTML, CSS
- Software License: MIT
- Standards: PURL v1.0
This crate is an implementation of the Package URL specification for the Rust programming language.
- Base language: Rust
- Software License: MIT
- Standards: PURL v1.0
.NET implementation of the package url spec.
- Base language: C#
- Software License: MIT
- Standards: PURL v1.0
Go implementation of the package url spec.
- Base language: Go
- Software License: MIT
- Standards: PURL v1.0
This project implements a purl parser and class for Java.
- Base language: Java
- Software License: MIT
- Standards: PURL v1.0
JavaScript implementation of the package url spec
- Base language: JavaScript
- Software License: MIT
- Standards: PURL v1.0
A parser and builder based on package url spec, implemented in PHP.
- Base language: PHP
- Software License: MIT
- Standards: PURL v1.0
Python implementation of the package url spec.
- Base language: Python
- Software License: MIT
- Standards: PURL v1.0
A Ruby implementation of the package url specification.
- Base language: Ruby
- Software License: MIT
- Standards: PURL v1.0
Swift implementation of the package url spec
- Base language: Swift
- Software License: MIT
- Standards: PURL v1.0
A pure-Julia implementation of the Package URL (PURL) specification
- Base language: Julia
- Software License: MIT
- Standards: PURL v1.0
A Perl implementation of PURL and VERS
- Base language: Perl
- Software License: Artistic-2.0
- Standards: PURL v1.0, VERS
A simple webapp that provides guidance on and creates Package URLs of type 'swid'.
- Base language: Vue
- Software License: MIT
- Standards: PURL v1.0
A Kotlin library for parsing and generating package-url
- Base language: Kotlin
- Software License: Apache-2.0
- Standards: PURL v1.0
PURL - Package URL specification v1.0.X
- Base language: Raku
- Software License: Artistic-2.0
- Standards: PURL v1.0
Advisory database for Python packages published on pypi.org
- Base language: Shell
- Standards: PURL v1.0
Reports PURLs and collects VERS from parsed package manifests using https.
- Base language: Python
- Software License: Apache-2.0
- Standards: PURL v1.0, VERS
Collects VERS from scanned and matched packages using https.
- Base language: Python
- Software License: Apache-2.0
- Standards: PURL v1.0, VERS
Accelerate issue resolution and software delivery by automating dependency management with Sonatype Lifecycle, an industry-best software composition analysis (SCA) tool recognized by Forrester.
- Standards: PURL v1.0
Software supply chain security platform for the enterprise to detect threats and exposures
- Standards: PURL v1.0
SW360 is a software component catalogue application designed to provide a central hub for managing software components and their metadata.
- Base language: Java
- Software License: EPL-2.0
- Standards: PURL v1.0
Parses and compares all package versions and ranges. For debian, npm, pypi, ruby and more.
- Base language: Python
- Software License: MIT
- Standards: VERS
Identifies vulnerabilities for a PURL.
- Base language: Python
- Software License: Apache-2.0
- Standards: PURL v1.0
A security intelligence platform providing unified access to vulnerabilities, advisories, and exploit data across ecosystems, leveraging PURL for consistent package identification.
- Standards: PURL v1.0













