ReARM: Open‑Source Release Manager and SBOM Repository

ReARM, short for “Reliza’s Artifact and Release Management,” is an open-source DevSecOps tool designed to help teams manage software releases alongside their supply chain metadata, particularly SBOMs (Software Bills of Materials). It lets you attach detailed dependency and component data to each release and stores this information in OCI-compliant storage. During the release process, ReARM can auto-generate aggregated BOMs, changelogs, and manage products and component versions. It integrates with vulnerability scanners like Dependency‑Track and CI systems such as GitHub Actions and Jenkins, enabling automated generation and submission of SBOMs and other release assets. The community edition is in public beta, with features like tracking nested artifacts, versioned releases, and TEA (Transparency Exchange API) support. It offers demo environments, CLI tools, documentation, and Helm or Docker‑Compose deployment scripts. ReARM is ideal for teams needing compliant, traceable release workflows without imposing heavy manual overhead 

https://github.com/relizaio/rearm

Comments

Popular posts from this blog

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities

OWASP SAMM Skills Framework Enhances Software Security Roles