GUAC – Aggregates Software Security Metadata Into A High Fidelity Graph Database

5f1574b107f23743f8353781079ce1d7dbd24671a86f8de9f7fec980f15c4b37


Note: GUAC is under active development – if you are interested in contributing, please look at contributor guide and the “express interest” issue

Graph for Understanding Artifact Composition (GUAC) aggregates software security metadata into a high fidelity graph database—normalizing entity identities and mapping standard relationships between them. Querying this graph can drive higher-level organizational outcomes such as audit, policy, risk management, and even developer assistance.


Conceptually, GUAC occupies the “aggregation and synthesis” layer of the software supply chain transparency logical model:

b373badedfc209eaca00308f8d71fdadb51e62299f97563c131dd37d9a00a780

A few examples of questions answered by GUAC include:

2e10c1265d8019e77142a8e7c71681ff39b9461568f4080f7a2b1c4b2a9dfd95

Quickstart

Refer to the Setup + Demo document to learn how to prepare your environment and try GUAC out!

Architecture

Here is an overview of the architecture of GUAC:

6c688549fe647519dfab6cefde9ebc605b97c48966228b3ba19ade56d3d8a80d

Supported input formats

Additional References

Communication

We encourage discussions to be done on github issues. We also have a public slack channel on the OpenSSF slack.

For security issues or code of conduct concerns, an e-mail should be sent to [email protected].

Governance

Information about governance can be found here.




Original Source


A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon using the button below

Digital Patreon Wordmark FieryCoralv2

To keep up to date follow us on the below channels.

join
Click Above for Telegram
discord
Click Above for Discord
reddit
Click Above for Reddit
hd linkedin
Click Above For LinkedIn