Todas las etiquetas
Etiqueta del catálogo

#supply-chain-security

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

51 registros
Con la etiqueta «supply-chain-security»Ordenado por índice de salud
Go
75Buenoíndice de salud
saschagrunert/nri-supply-chain
NRI plugin for supply chain attestation verification.
Go★ 29 ago 2026
Apache-2.09 ago 2026 · métricas 2.10.0
PyPI
73Buenoíndice de salud
b7n0de/proofbundle
Offline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth
Python★ 2↓ 6574/mes23 jul 2026
MIT23 jul 2026 · métricas 2.10.0
Go
73Buenoíndice de salud
github/actions-lockfile
The authoritative definition of the GitHub Actions dependency lockfile format, plus a Go parser for auditing and verifying the action pins in use across a repo's workflows.
Go★ 33 ago 2026
MIT3 ago 2026 · métricas 2.10.0
PyPI · npm
71Buenoíndice de salud
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6171/mes19 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go
69Buenoíndice de salud
optimuslabs-io/grokpatrol
Open-source, offline forensic scanner CLI tool designed to detect evidence of git repo collection or upload by the Grok Build CLI to xAI infrastructure.
Go★ 1218 jul 2026
Apache-2.018 jul 2026 · métricas 2.10.0
Go · npm
67Buenoíndice de salud
codeswhat/lookout
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 316 jul 2026
Licencia propia16 jul 2026 · métricas 2.10.0
crates.io
67Buenoíndice de salud
pulseengine/sigil
Sigil — Supply chain security for WebAssembly. Embedded signatures, Sigstore keyless signing, SLSA provenance. Part of the PulseEngine toolchain.
Rust★ 05 ago 2026
Sin licencia5 ago 2026 · métricas 2.10.0
npm
67Buenoíndice de salud
starloghq/index
Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.
TypeScript★ 9↓ 591/mes6 sept 2026
Licencia propia6 sept 2026 · métricas 2.10.0
Go
67Buenoíndice de salud
tiagosilva07/zyrax-guard
Audit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 228 ago 2026
MIT28 ago 2026 · métricas 2.10.0
crates.io
65Buenoíndice de salud
sebastienrousseau/dtt
Rust crate for date, time, and timezone manipulation. Parse, format, validate, and convert RFC 3339 / ISO 8601 with guaranteed round-trip safety.
Rust★ 7↓ 5328/mes25 jul 2026
Apache-2.025 jul 2026 · métricas 2.10.0
Go
63Moderadoíndice de salud
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317 jul 2026
MIT17 jul 2026 · métricas 2.10.0
PyPI
62Moderadoíndice de salud
sunglasses-dev/sunglasses
Sunglasses for AI agents. Protection layer + neighborhood watch.
Python★ 4↓ 2911/mes18 ago 2026
MIT18 ago 2026 · métricas 2.10.0
npm
60Moderadoíndice de salud
calllint/calllint
Pre-flight risk linting for MCP and agent tools — check the blast radius before your agent runs them.
TypeScript · HTML★ 2↓ 3504/mes31 jul 2026
Apache-2.031 jul 2026 · métricas 2.10.0
Go
59Moderadoíndice de salud
Goryudyuma/gomod-cooldown
Delay newly available Go module versions during dependency updates with a temporary local GOPROXY.
Go★ 015 jul 2026
MIT15 jul 2026 · métricas 2.10.0
Packagist
59Moderadoíndice de salud
andreapollastri/checkpoint
Laravel Security Tool
PHP★ 114↓ 19.3K/mes22 ago 2026
MIT22 ago 2026 · métricas 2.10.0
Go
57Moderadoíndice de salud
Conalh/tofulock
Lock & verify Terraform/OpenTofu module sources by commit digest - the integrity providers get from the native lockfile, but modules don't.
Go★ 027 jul 2026
MIT27 jul 2026 · métricas 2.10.0
Go
56Moderadoíndice de salud
sairintechnologycom/pkgsafe
Supply-chain firewall for AI coding agents and developers — checks npm/PyPI packages against OSV advisories, typosquat & lifecycle-script heuristics, and your policy before install. Local-first, MCP-native.
Go★ 015 jul 2026
MIT15 jul 2026 · métricas 2.10.0
Go · npm
54Moderadoíndice de salud
undont/supplyscan
scan JavaScript lockfiles to detect supply chain vulnerabilities and known exploits
Go★ 022 jul 2026
MIT22 jul 2026 · métricas 2.10.0
PyPI
54Moderadoíndice de salud
zrk222/code-factory
Proof-first software factory for AI-assisted code: specs, adversarial gates, deterministic decisions, and reviewable receipts.
Python★ 0↓ 2590/mes17 jul 2026
Licencia propia17 jul 2026 · métricas 2.10.0
PyPI
53Moderadoíndice de salud
meidielo/aes-256-gcm-python-tool
Reviewable AES-256-GCM educational tool with Argon2id, JSON envelopes, and safe-mode streaming.
Python · HTML★ 0↓ 77/mes19 jul 2026
MIT19 jul 2026 · métricas 2.10.0
Go
47Débilíndice de salud
wille/gh-actions-cli
Harden and manage your GitHub Actions: SHA-pin every action, enforce allowlist policies, update interactively, and analyze run health
Go★ 317 jul 2026
MIT17 jul 2026 · métricas 2.10.0