Repository navigation

#

software-supply-chain-security

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.

Go
1111
1 个月前

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Python
835
1 天前

An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

Go
758
10 个月前

Software Supply Chain Security Platform

Go
352
2 天前

in-toto Attestation Framework

Rust
300
1 天前

An open-source dataset of malicious software packages found in the wild, 100% vetted by humans.

Python
238
3 天前

Faster builds, zero effort.

Rust
202
1 个月前

Cross-platform embeddable sandboxing

Rust
193
2 个月前

A tool for preventing the installation of malicious npm and PyPI packages 🔥

Python
166
1 天前

A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.

137
2 年前

Enabling Software Supply Chain Security Capabilities in ArgoCD

Go
88
3 年前

Compage - Low-Code Framework to develop Rest API, gRPC, dRPC, GraphQL, WebAssembly, microservices, FaaS, Temporal workloads, IoT and edge services, K8s controllers, K8s CRDs, K8s custom APIs, K8s Operators, K8s hooks, etc. with minimal coding and by automatically applying best practice methods like software supply chain security measures, SBOM, openAPI, cloudevents, etc. Auto generate code after defining requirements in UI as diagram.

Go
85
1 年前

ReARM - Supply Chain Security and Asset Management for Releases, SBOMs, xBOMs, Security Artifacts

Java
82
2 天前

in-toto is a framework to secure the software supply chain.

71
9 个月前