Repository navigation

#

software-supply-chain

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

Go
1731
19 天前

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.

Go
1099
9 天前

An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

Go
755
8 个月前

Software Supply Chain Security Platform

Go
348
1 天前

全语言制品仓库,涵盖npm、Maven、PyPi、Docker、Gradle、SBT、Cocoapods、Swift、RPM、Debian、PHP、Go、Pub、Ivy、NuGet、Conda、Cargo、Conan、Yarn、GitLFS、Helm、OHPM等主流工具,涵盖Huggingface 等主流AI模型仓库的代理与同步

Java
290
13 天前

Software Component Verification Standard (SCVS)

Python
149
5 个月前

A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.

Go
140
9 天前

Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages

Java
135
3 年前

in-toto is a framework to secure the software supply chain.

70
7 个月前

ReARM - Supply Chain Security and Asset Management for Releases, SBOMs, xBOMs, Security Artifacts

Java
56
3 小时前

Github Action implementation of SLSA Provenance Generation

Go
50
1 天前

A rust implementation of in-toto

Rust
34
8 天前

A simple web app software supply chain monitoring toolkit

JavaScript
12
3 年前