#supply-chain (18 Repositories)
Ranked open-source repositories tagged with #supply-chain, scored by pull request acceptance likelihood and maintainer engagement velocity.
43.0%
32.9h
18 repositories tagged #supply-chain
phylum-dev/cli
Command line interface for the Phylum API
relizaio/rearm
ReARM - Release Governance Platform
guacsec/guac
GUAC aggregates software security metadata into a high fidelity graph database.
kpcyrd/rebuilderd
Independent verification of binary packages - Reproducible Builds
mindersec/minder
Software Supply Chain Security Platform
sigstore/rekor
Software Supply Chain Transparency Log
nsacyber/HIRS
Trusted Computing based services supporting TPM provisioning and supply chain validation concepts. #nsacyber
openvex/vexctl
A tool to create, transform and attest VEX metadata
fosslight/fosslight
FOSSLight Hub : Integrated management web-service for Open Source Compliance Process
sigstore/sigstore-python
A Sigstore client written in Python
theupdateframework/go-tuf
Go implementation of The Update Framework (TUF)
sigstore/sigstore
Common go library shared across sigstore services and clients
stacklok/frizbee
Throw a tag at it and it comes back with a checksum.
liyuqin606-del/packrehearsal
Turn npm, Python, and Rust release evidence into bounded Codex maintenance tasks.
cackle-rs/cackle
A code ACL checker for Rust
ossf/best-practices-badge
🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
sandworm-hq/sandworm-audit
Security & License Compliance For Your App's Dependencies 🪱
projectdiscovery/depx
Malicious package & supply-chain intelligence