Todas las etiquetas
Etiqueta del catálogo

#supply-chain-security

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

32 registros
Con la etiqueta «supply-chain-security»Ordenado por índice de salud
Go
85Excelenteíndice de salud
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
PyPI · npm
80Buenoíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
npm
77Buenoíndice de salud
lirantal/npq
safely install npm packages by auditing them pre-install stage
JavaScript★ 1759↓ 35.4K/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Go · npm
77Buenoíndice de salud
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 46417 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Go
76Buenoíndice de salud
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 5421 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
crates.io
75Buenoíndice de salud
always-further/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 303617 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
crates.io
75Buenoíndice de salud
lukehinds/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 304719 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
crates.io
74Buenoíndice de salud
nolabs-ai/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 301616 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
npm · PyPI
71Buenoíndice de salud
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 14.1K/mes14 jul 2026
AGPL-3.014 jul 2026 · métricas 1.13.0
Go · PyPI
71Buenoíndice de salud
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Go · PyPI
71Buenoíndice de salud
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 316 jul 2026
MIT16 jul 2026 · métricas 1.13.0
Go
71Buenoíndice de salud
sisaku-security/sisakulint
CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
Go★ 4219 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
PyPI · npm
70Buenoíndice de salud
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript · JavaScript★ 39615 jul 2026
Licencia propia15 jul 2026 · métricas 1.13.0
PyPI
68Moderadoíndice de salud
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1928/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Go
67Moderadoíndice de salud
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 2420 jul 2026
Apache-2.020 jul 2026 · métricas 1.13.0
PyPI
67Moderadoíndice de salud
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/mes14 jul 2026
Licencia propia14 jul 2026 · métricas 1.13.0
Go
66Moderadoíndice de salud
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 821 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
Go
65Moderadoíndice de salud
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
Go
64Moderadoíndice de salud
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 221 jul 2026
BSD-3-Clause21 jul 2026 · métricas 1.13.0
PyPI · npm
62Moderadoíndice de salud
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6171/mes19 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
Go
61Moderadoíndice de salud
optimuslabs-io/grokpatrol
Open-source, offline forensic scanner CLI tool designed to detect evidence of git repo collection or upload by the Grok Build CLI to xAI infrastructure.
Go★ 1218 jul 2026
Apache-2.018 jul 2026 · métricas 1.13.0
Go · npm
60Moderadoíndice de salud
codeswhat/lookout
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 316 jul 2026
Licencia propia16 jul 2026 · métricas 1.13.0
npm
59Moderadoíndice de salud
starloghq/index
Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.
TypeScript★ 7↓ 2182/mes15 jul 2026
Licencia propia15 jul 2026 · métricas 1.13.0
Go
58Moderadoíndice de salud
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317 jul 2026
MIT17 jul 2026 · métricas 1.13.0
Go
56Moderadoíndice de salud
Goryudyuma/gomod-cooldown
Delay newly available Go module versions during dependency updates with a temporary local GOPROXY.
Go★ 015 jul 2026
MIT15 jul 2026 · métricas 1.13.0
Go
54Moderadoíndice de salud
jitpass/jit
jit is an open-source CLI that finds the plaintext secrets scattered across a Mac and converts them into just-in-time, Touch-ID-gated credentials, without breaking anything that reads them.
Go★ 215 jul 2026
Licencia propia15 jul 2026 · métricas 1.13.0
Go
54Moderadoíndice de salud
sairintechnologycom/pkgsafe
Supply-chain firewall for AI coding agents and developers — checks npm/PyPI packages against OSV advisories, typosquat & lifecycle-script heuristics, and your policy before install. Local-first, MCP-native.
Go★ 015 jul 2026
MIT15 jul 2026 · métricas 1.13.0
PyPI
54Moderadoíndice de salud
zrk222/code-factory
Proof-first software factory for AI-assisted code: specs, adversarial gates, deterministic decisions, and reviewable receipts.
Python★ 0↓ 2590/mes17 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
Go · npm
53Moderadoíndice de salud
undont/supplyscan
scan JavaScript lockfiles to detect supply chain vulnerabilities and known exploits
Go★ 022 jul 2026
MIT22 jul 2026 · métricas 1.13.0
PyPI
52Moderadoíndice de salud
meidielo/aes-256-gcm-python-tool
Reviewable AES-256-GCM educational tool with Argon2id, JSON envelopes, and safe-mode streaming.
Python · HTML★ 0↓ 77/mes19 jul 2026
MIT19 jul 2026 · métricas 1.13.0