Todas las etiquetas
Etiqueta del catálogo

#supply-chain

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

14 registros
Con la etiqueta «supply-chain»Ordenado por índice de salud
Go · npm
84Buenoíndice de salud
mindersec/minder
Software Supply Chain Security Platform
Go★ 41220 jul 2026
Apache-2.020 jul 2026 · métricas 1.13.0
Go
82Buenoíndice de salud
Sigstore/rekor
Software Supply Chain Transparency Log
Go★ 117718 jul 2026
Apache-2.018 jul 2026 · métricas 1.13.0
PyPI · npm
80Buenoíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
Go
76Buenoíndice de salud
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 5421 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
npm · Maven · NuGet +1
76Buenoíndice de salud
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1012↓ 719.2K/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
npm · PyPI
71Buenoíndice de salud
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 14.1K/mes14 jul 2026
AGPL-3.014 jul 2026 · métricas 1.13.0
npm
71Buenoíndice de salud
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2247/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0
PyPI · npm
62Moderadoíndice de salud
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6171/mes19 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
Go
61Moderadoíndice de salud
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 119 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
npm · PyPI
59Moderadoíndice de salud
HikaruEgashira/pmsec
Zero-config supply-chain hardening.
PowerShell · Shell · Python★ 3↓ 3872/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0
npm
54Moderadoíndice de salud
adamsjack711-ux/pkgxray
Local CLI/MCP tool that audits AI-agent extensions and npm packages for supply-chain risk. Zero-dep Node. Static scan + OSV vuln precheck + sandboxed quarantine.
JavaScript★ 6↓ 4133/mes17 jul 2026
MIT17 jul 2026 · métricas 1.13.0
npm
53Moderadoíndice de salud
nkratk/llm-trust-guard
El repositorio no publica descripción.
TypeScript★ 1↓ 3299/mes19 jul 2026
MIT19 jul 2026 · métricas 1.13.0
npm
49En riesgoíndice de salud
iyulab/formulab
TypeScript library of 174 research-backed industrial engineering formulas across 14 domains — quality, metallurgy, logistics, safety, machining, and more — with zero dependencies.
TypeScript★ 0↓ 2186/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0
PyPI
39En riesgoíndice de salud
pypa/pip-audit
Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them
Python★ 1333↓ 24.2M/mes20 jul 2026
Apache-2.020 jul 2026 · métricas 1.13.0