<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Automation on OpenChain KWG</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/tags/automation/</link><description>Recent content in Automation on OpenChain KWG</description><generator>Hugo</generator><language>en</language><atom:link href="https://OpenChain-Project.github.io/OpenChain-KWG/en/tags/automation/index.xml" rel="self" type="application/rss+xml"/><item><title>Building an Automated Open Source Management Environment: cdxgen + Dependency-Track</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/guide/tools/8-cdxgen-dt/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/guide/tools/8-cdxgen-dt/</guid><description>&lt;p&gt;For companies just starting with open source management, we recommend the
&lt;strong&gt;cdxgen + Dependency-Track&lt;/strong&gt; combination as a toolset that can establish a basic
automation environment within a single day.&lt;/p&gt;
&lt;p&gt;This guide walks you through every step, from installation and configuration to
setting up a license and vulnerability inspection environment and running day-to-day operations.&lt;/p&gt;
&lt;h2 id="why-cdxgen--dependency-track"&gt;Why cdxgen + Dependency-Track&lt;/h2&gt;
&lt;p&gt;Open source management comes down to two essentials.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Know what is inside&lt;/strong&gt; — generating an SBOM (Software Bill of Materials)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Continuously monitor risk&lt;/strong&gt; — detecting vulnerabilities (CVEs) and license policy violations&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;cdxgen handles the first, and Dependency-Track handles the second.
Both tools are &lt;strong&gt;free open source&lt;/strong&gt; under the Apache-2.0 license.&lt;/p&gt;</description></item></channel></rss>