software-supply-chain topic
go-malice
A malicious package to demonstrate the importance of software supply chain security.
murphysec
An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。
chain-bench
An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
Software-Component-Verification-Standard
Software Component Verification Standard (SCVS)
maloss
Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages
in-toto-golang
A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.
awesome-software-supply-chain-security
A compilation of resources in the software supply chain security domain, with emphasis on open source
dependency-check-py
:closed_lock_with_key: Shim to easily install OWASP dependency-check-cli into Python projects
slsa-provenance-action
Github Action implementation of SLSA Provenance Generation
in-toto-rs
A rust implementation of in-toto