All tags
Catalogue tag

#software-supply-chain

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

6 records
Tagged “software-supply-chain”Ranked by health index
Go · npm
97Exceptionalhealth index
mindersec/minder
Software Supply Chain Security Platform
Go★ 412Jul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 2.10.0
PyPI · crates.io · Go +1
92Excellenthealth index
in-toto/attestation
in-toto Attestation Framework
Rust★ 369↓ 44.4K/moAug 29, 2026
Custom licenseAug 29, 2026 · metrics 2.10.0
Go
78Goodhealth index
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 24Jul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 2.10.0
Go
73Goodhealth index
in-toto/in-toto-golang
A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.
Go★ 151Aug 29, 2026
Custom licenseAug 29, 2026 · metrics 2.10.0
npm · PyPI
63Moderatehealth index
HikaruEgashira/pmsec
Zero-config supply-chain hardening.
PowerShell · Shell · Python★ 3↓ 3,872/moJul 15, 2026
MITJul 15, 2026 · metrics 2.10.0
Go
53Moderatehealth index
open-delivery-spec/cli
Reference CLI tool for Open Delivery Spec — validate and generate delivery artifacts
Go★ 0Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0