Abbreviations and Descriptions
Glossary of terms used in Safeguard.sh documentation
A comprehensive glossary of terms and abbreviations used throughout Safeguard.sh documentation.
| Term | Description |
|---|
| ESSCM | Enterprise Software Supply Chain Manager |
| OSM | Open Source Manager |
| TPRM | Third Party Risk Manager |
| Portal | Centralized SBOM management platform |
| Griffin AI | Purpose-built LLM for supply chain security |
| AI Remediate | Automated vulnerability remediation feature |
| Term | Description |
|---|
| CVE | Common Vulnerabilities and Exposures |
| CVSS | Common Vulnerability Scoring System |
| EPSS | Exploit Prediction Scoring System |
| KEV | Known Exploited Vulnerabilities (CISA catalog) |
| NVD | National Vulnerability Database |
| Term | Description |
|---|
| SBOM | Software Bill of Materials |
| SPDX | Software Package Data Exchange format |
| CycloneDX | OWASP SBOM format |
| VEX | Vulnerability Exploitability eXchange |
| PURL | Package URL - universal package identifier |
| Term | Description |
|---|
| SLSA | Supply chain Levels for Software Artifacts |
| SSDF | Secure Software Development Framework |
| SCA | Software Composition Analysis |
| ESCM | Software Supply Chain Management |
| Term | Description |
|---|
| EO 14028 | Executive Order 14028 on Cybersecurity |
| FedRAMP | Federal Risk and Authorization Management Program |
| IL7 | Impact Level 7 (DoD classification) |
| NTIA | National Telecommunications and Information Administration |
| SOC 2 | Service Organization Control 2 |
| Term | Description |
|---|
| ACR | Azure Container Registry |
| ECR | Elastic Container Registry (AWS) |
| GCR | Google Container Registry |
| OCI | Open Container Initiative |
| SCM | Source Code Management |
| Term | Description |
|---|
| SSO | Single Sign-On |
| SAML | Security Assertion Markup Language |
| OIDC | OpenID Connect |
| SCIM | System for Cross-domain Identity Management |
| MFA | Multi-Factor Authentication |
A formal, structured list of components, libraries, and modules that make up a piece of software, along with their relationships and metadata.
Safeguard.sh's automated remediation feature powered by Griffin AI that generates pull requests to fix vulnerabilities.
A measure of package integrity and trustworthiness based on malicious package detection, supply chain verification, and provenance attestation.
Overall security scoring based on the package itself, including vulnerability count, severity distribution, maintenance status, and community trust.