Todas las etiquetas
Etiqueta del catálogo

#supply-chain

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

37 registros
Con la etiqueta «supply-chain»Ordenado por índice de salud
Go
98Excepcionalíndice de salud
sigstore/sigstore
Common go library shared across sigstore services and clients
Go★ 53329 ago 2026
Apache-2.029 ago 2026 · métricas 2.10.0
Go · npm
97Excepcionalíndice de salud
mindersec/minder
Software Supply Chain Security Platform
Go★ 41220 jul 2026
Apache-2.020 jul 2026 · métricas 2.10.0
PyPI
96Excepcionalíndice de salud
sigstore/sigstore-python
A Sigstore client written in Python
Python★ 332↓ 1M/mes11 ago 2026
Licencia propia11 ago 2026 · métricas 2.10.0
Go
95Excepcionalíndice de salud
Sigstore/rekor
Software Supply Chain Transparency Log
Go★ 117718 jul 2026
Apache-2.018 jul 2026 · métricas 2.10.0
PyPI
95Excepcionalíndice de salud
pypa/pip-audit
Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them
Python★ 1356↓ 31M/mes27 ago 2026
Apache-2.027 ago 2026 · métricas 2.10.0
PyPI · npm
94Excepcionalíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
npm
93Excepcionalíndice de salud
sigstore/sigstore-js
Code-signing for npm packages
TypeScript★ 181↓ 172M/mes31 ago 2026
Apache-2.031 ago 2026 · métricas 2.10.0
npm · Maven · NuGet +1
92Excelenteíndice de salud
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1018↓ 745.3K/mes28 jul 2026
Apache-2.028 jul 2026 · métricas 2.10.0
Go
90Excelenteíndice de salud
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 5421 jul 2026
Apache-2.021 jul 2026 · métricas 2.10.0
Go · npm
89Excelenteíndice de salud
seebom-labs/BOMHort
About standalone, Kubernetes-native Software Bill of Materials (SBOM) visualization and governance platform
Go · TypeScript★ 2829 jul 2026
Apache-2.029 jul 2026 · métricas 2.10.0
npm
88Excelenteíndice de salud
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5893/mes6 sept 2026
MIT6 sept 2026 · métricas 2.10.0
npm
86Excelenteíndice de salud
blamejs/blamejs
The Node framework that owns its stack.
JavaScript★ 3↓ 15.2K/mes22 ago 2026
Apache-2.022 ago 2026 · métricas 2.10.0
Go · npm
86Excelenteíndice de salud
emoss08/Trenova
An AI-driven asset based Transportation Management System
Go · TypeScript★ 723 ago 2026
Licencia propia3 ago 2026 · métricas 2.10.0
crates.io
86Excelenteíndice de salud
rust-secure-code/cargo-auditable
Make production Rust binaries auditable
Rust★ 849↓ 3M/mes5 sept 2026
Apache-2.05 sept 2026 · métricas 2.10.0
npm · PyPI
84Excelenteíndice de salud
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 7189/mes22 ago 2026
AGPL-3.022 ago 2026 · métricas 2.10.0
npm
77Buenoíndice de salud
blamejs/pki
Pure-JavaScript PKI toolkit that owns its stack — X.509, ASN.1/DER, CMS, PQC-first.
JavaScript★ 1↓ 11.7K/mes23 jul 2026
Apache-2.023 jul 2026 · métricas 2.10.0
PyPI · npm
71Buenoíndice de salud
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6171/mes19 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
PyPI
69Buenoíndice de salud
Ndevu12/stayAwakeBot
A bot for helping you to stay secure and making free hosted services stay a wake
Python★ 231 jul 2026
AGPL-3.031 jul 2026 · métricas 2.10.0
npm
69Buenoíndice de salud
abpai/harness-doctor
Framework-agnostic agent-harness doctor: deterministic checks for good agent-harness practices
TypeScript★ 0↓ 6723/mes23 jul 2026
MIT23 jul 2026 · métricas 2.10.0
Packagist
69Buenoíndice de salud
dgtlss/warden
A Laravel package that proactively monitors your dependencies for security vulnerabilities by running automated composer audits and sending notifications via webhooks and email
PHP★ 97↓ 7100/mes5 sept 2026
MIT5 sept 2026 · métricas 2.10.0
npm
69Buenoíndice de salud
dot-skill/skillerr
Open .skill Protocol - a sealed, inspectable package format for AI agent skills. Reference implementation: skillerr.
TypeScript · JavaScript★ 3↓ 35.3K/mes27 jul 2026
Apache-2.027 jul 2026 · métricas 2.10.0
Go
67Buenoíndice de salud
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 119 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go
65Buenoíndice de salud
matteo-sung/lockvet
Explain any lockfile change: bumps release-verified against 22 registries, vulns (OSV), ages, deprecations, typosquats, integrity tampering — 61 formats incl. pdm.lock, vcpkg, mise.lock, build.gradle, pom.xml, go.sum, GitHub Actions, GitLab CI, Dockerfiles, Kubernetes, Helm, SBOMs. CLI + CI gate + MCP server + playground. By an AI agent.
Go★ 023 ago 2026
MIT23 ago 2026 · métricas 2.10.0
npm · PyPI
63Moderadoíndice de salud
HikaruEgashira/pmsec
Zero-config supply-chain hardening.
PowerShell · Shell · Python★ 3↓ 3872/mes15 jul 2026
MIT15 jul 2026 · métricas 2.10.0
Go · npm
63Moderadoíndice de salud
cjohnstoniv/wardyn
Open-source governance control plane for coding agents — per-run identity, brokered credentials, layered egress, approvals, and an append-only audit. Apache-2.0, self-hosted.
Go · TypeScript★ 227 jul 2026
Apache-2.027 jul 2026 · métricas 2.10.0
Go · npm
63Moderadoíndice de salud
daimoniac/suppline
Self-hosted Kubernetes image intake gateway: mirror → Trivy scan → CEL policy → Sigstore attestations. Admit only what passed.
Go · TypeScript★ 530 jul 2026
Apache-2.030 jul 2026 · métricas 2.10.0
PyPI
60Moderadoíndice de salud
YugantM/hvtracker
AI Agent Trust Registry — independent, evidence-based trust scores for 300+ open-source AI agents. Runtime-trust calibrated (MCP, dependencies, provenance drift), with side-by-side comparison and embeddable live badges. Ranked by verifiable signals, not hype.
HTML★ 526 jul 2026
MIT26 jul 2026 · métricas 2.10.0
crates.io
60Moderadoíndice de salud
cackle-rs/cackle
A code ACL checker for Rust
Rust★ 286↓ 84/mes16 ago 2026
Licencia propia16 ago 2026 · métricas 2.10.0
npm
60Moderadoíndice de salud
calllint/calllint
Pre-flight risk linting for MCP and agent tools — check the blast radius before your agent runs them.
TypeScript · HTML★ 2↓ 3504/mes31 jul 2026
Apache-2.031 jul 2026 · métricas 2.10.0
npm
59Moderadoíndice de salud
extensiondev/artifact-integrity
Trust what you ship: download and verify browser extension artifacts (zip structure, manifest, metadata) and emit a deterministic JSON report for CI release gates.
TypeScript · JavaScript★ 0↓ 3717/mes25 jul 2026
Apache-2.025 jul 2026 · métricas 2.10.0