All tags
Catalogue tag

#supply-chain

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

14 records
Tagged “supply-chain”Ranked by health index
Go · npm
84Goodhealth index
mindersec/minder
Software Supply Chain Security Platform
Go★ 412Jul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 1.13.0
Go
82Goodhealth index
Sigstore/rekor
Software Supply Chain Transparency Log
Go★ 1,177Jul 18, 2026
Apache-2.0Jul 18, 2026 · metrics 1.13.0
PyPI · npm
80Goodhealth index
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 1.13.0
Go
76Goodhealth index
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 54Jul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0
npm · Maven · NuGet +1
76Goodhealth index
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1,012↓ 719.2K/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
npm · PyPI
71Goodhealth index
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 14.1K/moJul 14, 2026
AGPL-3.0Jul 14, 2026 · metrics 1.13.0
npm
71Goodhealth index
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2,247/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
PyPI · npm
62Moderatehealth index
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6,171/moJul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 1.13.0
Go
61Moderatehealth index
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 1Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 1.13.0
npm · PyPI
59Moderatehealth index
HikaruEgashira/pmsec
Zero-config supply-chain hardening.
PowerShell · Shell · Python★ 3↓ 3,872/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
npm
54Moderatehealth index
adamsjack711-ux/pkgxray
Local CLI/MCP tool that audits AI-agent extensions and npm packages for supply-chain risk. Zero-dep Node. Static scan + OSV vuln precheck + sandboxed quarantine.
JavaScript★ 6↓ 4,133/moJul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
npm
53Moderatehealth index
nkratk/llm-trust-guard
No repository description published.
TypeScript★ 1↓ 3,299/moJul 19, 2026
MITJul 19, 2026 · metrics 1.13.0
npm
49At riskhealth index
iyulab/formulab
TypeScript library of 174 research-backed industrial engineering formulas across 14 domains — quality, metallurgy, logistics, safety, machining, and more — with zero dependencies.
TypeScript★ 0↓ 2,186/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
PyPI
39At riskhealth index
pypa/pip-audit
Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them
Python★ 1,333↓ 24.2M/moJul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 1.13.0