Repository navigation

#

supply-chain-security

Supply-chain Levels for Software Artifacts

Shell
1735
3 天前

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.

Python
1166
1 个月前

Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.

Python
1003
2 年前

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

TypeScript
890
2 天前

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

Go
814
6 个月前

Packj stops ⚡ Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain

Python
673
2 年前

Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more

Go
493
1 天前
Shell
408
2 天前

BLint is a Binary Linter to check the security properties, and capabilities in your executables. Since v2, blint is also an SBOM generator for binaries.

Python
404
1 天前

Independent verification of binary packages - Reproducible Builds

Rust
403
1 个月前

Orchestrate GitHub Actions Security

Go
295
2 个月前

Developer-centric tool to secure your software supply chain.

Go
291
10 个月前

JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

TypeScript
256
4 天前

sbomqs: The Comprehensive SBOM Quality & Compliance Tool

Go
245
3 天前