{"adoption": {"forks": 190, "observed_at": "2026-08-28T04:03:14.961121+00:00", "stars": 1018}, "canonical_url": "https://ross.abutalabs.com/products/tern-tools-tern", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more. ", "domain": ["security", "developer-tools"], "enriched": true, "function": ["security", "developer-tools", "container-runtime", "parser"], "health_score": 21, "homepage": null, "language": "Python", "license": "BSD-2-Clause", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["tern-tools/tern"], "name": "tern-tools/tern", "platform": ["python", "cli"], "pushed_at": "2024-03-12T22:41:47+00:00", "repo": "tern-tools/tern", "stars": 1018, "tags": ["sbom", "spdx", "cyclonedx", "software-composition-analysis", "supply-chain-security", "dockerfile", "compliance", "oss-compliance", "containers", "devops", "linux", "docker"], "topics": ["python", "containers", "oss-compliance", "sbom", "docker", "compliance", "spdx", "tool", "dependencies", "software-composition-analysis", "risk-management", "open-source", "supply-chain-security", "metadata-extraction"], "urls": [], "use_cases": ["generate an SBOM for a docker image", "create a software bill of materials from a Dockerfile", "list packages installed in each container image layer", "export container dependencies in SPDX or CycloneDX format", "audit open source license compliance in container images", "scan container images for supply chain security"], "what_it_is": "Tern is a Python-based software composition analysis tool and library that generates a Software Bill of Materials (SBOM) for container images and Dockerfiles. It inspects each image layer to identify installed packages and their metadata, producing reports in human-readable, JSON, HTML, YAML, SPDX, and CycloneDX formats.", "when_to_avoid": ["you need SBOMs for non-container artifacts like binaries or OS packages outside images", "you need active vulnerability scanning as the primary feature (extensions like cve-bin-tool are optional)", "you need a tool with frequent recent releases or broad runtime support beyond Linux/Docker"], "when_to_choose": ["you need layer-by-layer package metadata for Docker images or Dockerfiles", "you need SBOM output in SPDX, CycloneDX, JSON, HTML, or YAML formats", "you want a Python library or CLI for container software composition analysis"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/tern-tools-tern", "repo": "tern-tools/tern", "role": "main", "score": 23}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T07:09:30.345531+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "616cd94a7f734e12c4ab4143af8a714754c011c97f222d2e9e8dfcf4f17ca6b2", "fetched_at": "2026-08-28T04:03:14.961121+00:00", "kind": "readme", "missing": false, "url": "https://github.com/tern-tools/tern"}, {"content_hash": "1e484586dba8ba248b377ca44469f64bfa01a92f33a68c00a4df92bac07ee3ac", "fetched_at": "2026-08-29T13:09:55.733840+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/tern/json"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T07:09:30.345531+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "616cd94a7f734e12c4ab4143af8a714754c011c97f222d2e9e8dfcf4f17ca6b2", "fetched_at": "2026-08-28T04:03:14.961121+00:00", "kind": "readme", "missing": false, "url": "https://github.com/tern-tools/tern"}, {"content_hash": "1e484586dba8ba248b377ca44469f64bfa01a92f33a68c00a4df92bac07ee3ac", "fetched_at": "2026-08-29T13:09:55.733840+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/tern/json"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T07:09:30.345531+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "616cd94a7f734e12c4ab4143af8a714754c011c97f222d2e9e8dfcf4f17ca6b2", "fetched_at": "2026-08-28T04:03:14.961121+00:00", "kind": "readme", "missing": false, "url": "https://github.com/tern-tools/tern"}, {"content_hash": "1e484586dba8ba248b377ca44469f64bfa01a92f33a68c00a4df92bac07ee3ac", "fetched_at": "2026-08-29T13:09:55.733840+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/tern/json"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T07:09:30.345531+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "616cd94a7f734e12c4ab4143af8a714754c011c97f222d2e9e8dfcf4f17ca6b2", "fetched_at": "2026-08-28T04:03:14.961121+00:00", "kind": "readme", "missing": false, "url": "https://github.com/tern-tools/tern"}, {"content_hash": "1e484586dba8ba248b377ca44469f64bfa01a92f33a68c00a4df92bac07ee3ac", "fetched_at": "2026-08-29T13:09:55.733840+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/tern/json"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T07:09:30.345531+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "616cd94a7f734e12c4ab4143af8a714754c011c97f222d2e9e8dfcf4f17ca6b2", "fetched_at": "2026-08-28T04:03:14.961121+00:00", "kind": "readme", "missing": false, "url": "https://github.com/tern-tools/tern"}, {"content_hash": "1e484586dba8ba248b377ca44469f64bfa01a92f33a68c00a4df92bac07ee3ac", "fetched_at": "2026-08-29T13:09:55.733840+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/tern/json"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T07:09:30.345531+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "616cd94a7f734e12c4ab4143af8a714754c011c97f222d2e9e8dfcf4f17ca6b2", "fetched_at": "2026-08-28T04:03:14.961121+00:00", "kind": "readme", "missing": false, "url": "https://github.com/tern-tools/tern"}, {"content_hash": "1e484586dba8ba248b377ca44469f64bfa01a92f33a68c00a4df92bac07ee3ac", "fetched_at": "2026-08-29T13:09:55.733840+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/tern/json"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:14.961121+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T07:09:30.345531+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "616cd94a7f734e12c4ab4143af8a714754c011c97f222d2e9e8dfcf4f17ca6b2", "fetched_at": "2026-08-28T04:03:14.961121+00:00", "kind": "readme", "missing": false, "url": "https://github.com/tern-tools/tern"}, {"content_hash": "1e484586dba8ba248b377ca44469f64bfa01a92f33a68c00a4df92bac07ee3ac", "fetched_at": "2026-08-29T13:09:55.733840+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/tern/json"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T07:09:30.345531+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "616cd94a7f734e12c4ab4143af8a714754c011c97f222d2e9e8dfcf4f17ca6b2", "fetched_at": "2026-08-28T04:03:14.961121+00:00", "kind": "readme", "missing": false, "url": "https://github.com/tern-tools/tern"}, {"content_hash": "1e484586dba8ba248b377ca44469f64bfa01a92f33a68c00a4df92bac07ee3ac", "fetched_at": "2026-08-29T13:09:55.733840+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/tern/json"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T07:09:30.345531+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "616cd94a7f734e12c4ab4143af8a714754c011c97f222d2e9e8dfcf4f17ca6b2", "fetched_at": "2026-08-28T04:03:14.961121+00:00", "kind": "readme", "missing": false, "url": "https://github.com/tern-tools/tern"}, {"content_hash": "1e484586dba8ba248b377ca44469f64bfa01a92f33a68c00a4df92bac07ee3ac", "fetched_at": "2026-08-29T13:09:55.733840+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/tern/json"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T07:09:30.345531+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "616cd94a7f734e12c4ab4143af8a714754c011c97f222d2e9e8dfcf4f17ca6b2", "fetched_at": "2026-08-28T04:03:14.961121+00:00", "kind": "readme", "missing": false, "url": "https://github.com/tern-tools/tern"}, {"content_hash": "1e484586dba8ba248b377ca44469f64bfa01a92f33a68c00a4df92bac07ee3ac", "fetched_at": "2026-08-29T13:09:55.733840+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/tern/json"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3201, "days_push": 904, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 23, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}