Repository navigation

#

software-supply-chain

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

Go
1724
4 天前

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.

Go
1065
6 天前

An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

Go
745
4 个月前

Software Supply Chain Security Platform

Go
329
3 天前

Software Component Verification Standard (SCVS)

Python
143
19 天前

A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.

Go
137
4 天前

Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages

Java
132
3 年前

in-toto is a framework to secure the software supply chain.

70
3 个月前

Github Action implementation of SLSA Provenance Generation

Go
47
5 天前

A rust implementation of in-toto

Rust
31
2 个月前

A simple web app software supply chain monitoring toolkit

JavaScript
12
3 年前

The ChaordicLedger is the implementation of a design for a combination of Distributed Ledger Technology (DLT) and a Distributed File System (DFS) to create a secure, enterprise-grade platform for storing interlinked project artifacts.

Shell
9
6 天前