supply-chain-security
Here are 155 public repositories matching this topic...
Language:All
Sort:Most stars
Supply-chain Levels for Software Artifacts
- Updated
Mar 27, 2025 - Shell
GUAC aggregates software security metadata into a high fidelity graph database.
- Updated
Mar 27, 2025 - Go
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
- Updated
Mar 27, 2025 - Python
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
- Updated
Mar 12, 2024 - Python
Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets
- Updated
Mar 21, 2025 - Go
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
- Updated
Mar 25, 2025 - TypeScript
Packj stops ⚡ Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
- Updated
Apr 2, 2024 - Python
Evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
- Updated
Mar 27, 2025 - Go
Independent verification of binary packages - Reproducible Builds
- Updated
Mar 4, 2025 - Rust
BLint is a Binary Linter to check the security properties, and capabilities in your executables. Since v2, blint is also an SBOM generator for binaries.
- Updated
Mar 27, 2025 - Python
A compilation of resources in the software supply chain security domain, with emphasis on open source
- Updated
Apr 24, 2023
🚀 Policy driven vetting of open source packages with malicious code analysis
- Updated
Mar 26, 2025 - Go
Developer-centric tool to secure your software supply chain.
- Updated
Dec 17, 2024 - Go
Orchestrate GitHub Actions Security
- Updated
Mar 25, 2025 - Go
boostsecurityio/poutine
- Updated
Mar 1, 2025 - Go
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
- Updated
Mar 9, 2025 - JavaScript
Prevent merging of malicious code in pull requests
- Updated
Mar 20, 2025 - Python
SBOM quality score - Quality metrics for your sboms
- Updated
Mar 17, 2025 - Go
Improve this page
Add a description, image, and links to thesupply-chain-security topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with thesupply-chain-security topic, visit your repo's landing page and select "manage topics."