Yes. Since both Snyk and FOSSA can scan for C# dependencies, you can use Ketryx for dependencies and SBOM management.
Yes, Ketryx scans SPDX files and your vulnerability scanner can output in this format. It parses the SPDX file and creates corresponding dependencies as defined within these files. Ketryx extracts crucial information about software packages, including version, license, and advisory information (introduced in SPDX version 2.3), and checks direct and indirect (transitive) dependencies for vulnerabilities.
See MAN-03 - Supply Chain Management: Software Dependencies for more information.
Article is closed for comments.