ts-scan
Our Swiss army knife for software composition analysis (SCA). ts-scan allows you to assess all kinds of artefacts, whether source, package, or container. Assess and get your SBOM.
ts-scan supports several programming languages and therfore, guarantees a consistent behaviour across different CI/CD chains and projects.
In addition, you may define how deep the analysis will be performed. For certain cases or stages it may be sufficient to remain at the package level; for others you may want to go deeper. Both are possible by simply using a different verb.