supply-chain-security topic
auth-tarball-from-git
Authenticate a tarball through a signed tag in a git repository (with reproducible builds)
gocap
List your dependencies capabilities and monitor if updates require more capabilities.
sbom-operator
Catalogue all images of a Kubernetes cluster to multiple targets with Syft
tern
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-...
sdc-check
Small tool to inform you about potential risks in project dependencies list
js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
slsa
Supply-chain Levels for Software Artifacts
rebuilderd
Independent verification of binary packages - reproducible builds
pacman-bintrans
Experimental binary transparency for pacman with sigstore and rekor
legitify
Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets