Todas las etiquetas
Etiqueta del catálogo

#supply-chain-security

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

51 registros
Con la etiqueta «supply-chain-security»Ordenado por índice de salud
Go
98Excepcionalíndice de salud
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
npm
96Excepcionalíndice de salud
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
TypeScript★ 286↓ 14.6K/mes4 ago 2026
MIT4 ago 2026 · métricas 2.10.0
PyPI · npm
94Excepcionalíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
PyPI · npm
94Excepcionalíndice de salud
sattyamjjain/agent-audit-kit
Static scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2808/mes2 ago 2026
MIT2 ago 2026 · métricas 2.10.0
PyPI · crates.io · npm
93Excepcionalíndice de salud
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript★ 557↓ 95.5K/mes5 sept 2026
Apache-2.05 sept 2026 · métricas 2.10.0
Go · npm
92Excelenteíndice de salud
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 46417 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
Go
90Excelenteíndice de salud
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 5421 jul 2026
Apache-2.021 jul 2026 · métricas 2.10.0
npm
90Excelenteíndice de salud
lirantal/npq
safely install npm packages by auditing them pre-install stage
JavaScript★ 1759↓ 35.4K/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
crates.io
90Excelenteíndice de salud
nolabs-ai/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 301616 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
crates.io
89Excelenteíndice de salud
always-further/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 303617 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
crates.io
89Excelenteíndice de salud
lukehinds/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 304719 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go · npm
89Excelenteíndice de salud
seebom-labs/BOMHort
About standalone, Kubernetes-native Software Bill of Materials (SBOM) visualization and governance platform
Go · TypeScript★ 2829 jul 2026
Apache-2.029 jul 2026 · métricas 2.10.0
Go · PyPI
87Excelenteíndice de salud
IronSecCo/ironclaw
Security-first, self-hosted AI agents - isolation you can prove, not just promise.
Go★ 1929 ago 2026
AGPL-3.029 ago 2026 · métricas 2.10.0
Go
86Excelenteíndice de salud
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 024 jul 2026
Apache-2.024 jul 2026 · métricas 2.10.0
Go · PyPI
86Excelenteíndice de salud
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
Go · PyPI
86Excelenteíndice de salud
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 316 jul 2026
MIT16 jul 2026 · métricas 2.10.0
Go
86Excelenteíndice de salud
sisaku-security/sisakulint
CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
Go★ 4219 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
npm · PyPI
84Excelenteíndice de salud
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 7189/mes22 ago 2026
AGPL-3.022 ago 2026 · métricas 2.10.0
PyPI · npm
84Excelenteíndice de salud
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1281↓ 10.9K/mes24 ago 2026
MIT24 ago 2026 · métricas 2.10.0
PyPI
84Excelenteíndice de salud
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 5022 ago 2026
Licencia propia22 ago 2026 · métricas 2.10.0
Go · npm
83Excelenteíndice de salud
CodesWhat/portwing
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 415 ago 2026
AGPL-3.015 ago 2026 · métricas 2.10.0
Go
83Excelenteíndice de salud
liatrio/autogov
Unified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 11 ago 2026
Apache-2.01 ago 2026 · métricas 2.10.0
Go
81Excelenteíndice de salud
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 823 jul 2026
Apache-2.023 jul 2026 · métricas 2.10.0
npm · PyPI
80Excelenteíndice de salud
delimit-ai/delimit-mcp-server
The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.
Python · JavaScript★ 21↓ 3625/mes3 ago 2026
MIT3 ago 2026 · métricas 2.10.0
PyPI
78Buenoíndice de salud
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1928/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
Go
78Buenoíndice de salud
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 2420 jul 2026
Apache-2.020 jul 2026 · métricas 2.10.0
Go
77Buenoíndice de salud
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go
77Buenoíndice de salud
jitpass/jit
Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and local-first.
Go★ 1575 sept 2026
Licencia propia5 sept 2026 · métricas 2.10.0
Go
75Buenoíndice de salud
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 221 jul 2026
BSD-3-Clause21 jul 2026 · métricas 2.10.0
PyPI · npm
75Buenoíndice de salud
gautamvarmadatla/mcpsafetywarden
MCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Python★ 9↓ 2923/mes1 ago 2026
Licencia propia1 ago 2026 · métricas 2.10.0