#supply-chain-security (19 Repositories)
Ranked open-source repositories tagged with #supply-chain-security, scored by pull request acceptance likelihood and maintainer engagement velocity.
63.3%
21.6h
19 repositories tagged #supply-chain-security
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
openai/fence
A fence keeps things out, but also in. This project is still in early, and active development.
cicd-sensor/cicd-sensor
Open-source eBPF runtime security sensor for GitHub Actions and GitLab CI/CD.
guacsec/guac
GUAC aggregates software security metadata into a high fidelity graph database.
konflux-ci/konflux-ci
Trusted builds made easy! A cloud-native software factory for building, testing, and releasing trusted software artifacts
kpcyrd/rebuilderd
Independent verification of binary packages - Reproducible Builds
getnora-io/nora
Lightweight multi-format artifact registry. 15 formats: Docker, Maven, npm, PyPI, Cargo, Go, Raw, RubyGems, Terraform, Ansible Galaxy, NuGet, Pub, Conan, RPM, and Debian/APT. Single binary, zero dependencies, < 50 MB RAM idle.
nolabs-ai/nono
safe execution paths for agents - zero trust, zero setup, zero latency.
safedep/vet
Protect against malicious open source packages 🤖
step-security/dev-machine-guard
Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages - in seconds.
ckotzbauer/sbom-operator
Catalogue all images of a Kubernetes cluster to multiple targets with Syft
docker/scout-cli
Docker Scout CLI
sheeki03/tirith
Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.
step-security/secure-repo
Orchestrate GitHub Actions Security
projectdiscovery/depx
Malicious package & supply-chain intelligence
gensecaihq/Shai-Hulud-2.0-Detector
GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
perplexityai/bumblebee
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.