All tags
Catalogue tag

#supply-chain-security

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

51 records
Tagged “supply-chain-security”Ranked by health index
Go
98Exceptionalhealth index
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 570Jul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 2.10.0
npm
96Exceptionalhealth index
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
TypeScript★ 286↓ 14.6K/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
PyPI · npm
94Exceptionalhealth index
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 2.10.0
PyPI · npm
94Exceptionalhealth index
sattyamjjain/agent-audit-kit
Static scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2,808/moAug 2, 2026
MITAug 2, 2026 · metrics 2.10.0
PyPI · crates.io · npm
93Exceptionalhealth index
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript★ 557↓ 95.5K/moSep 5, 2026
Apache-2.0Sep 5, 2026 · metrics 2.10.0
Go · npm
92Excellenthealth index
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 464Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
Go
90Excellenthealth index
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 54Jul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 2.10.0
npm
90Excellenthealth index
lirantal/npq
safely install npm packages by auditing them pre-install stage
JavaScript★ 1,759↓ 35.4K/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
crates.io
90Excellenthealth index
nolabs-ai/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3,016Jul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 2.10.0
crates.io
89Excellenthealth index
always-further/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3,036Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
crates.io
89Excellenthealth index
lukehinds/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3,047Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
Go · npm
89Excellenthealth index
seebom-labs/BOMHort
About standalone, Kubernetes-native Software Bill of Materials (SBOM) visualization and governance platform
Go · TypeScript★ 28Jul 29, 2026
Apache-2.0Jul 29, 2026 · metrics 2.10.0
Go · PyPI
87Excellenthealth index
IronSecCo/ironclaw
Security-first, self-hosted AI agents - isolation you can prove, not just promise.
Go★ 19Aug 29, 2026
AGPL-3.0Aug 29, 2026 · metrics 2.10.0
Go
86Excellenthealth index
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 0Jul 24, 2026
Apache-2.0Jul 24, 2026 · metrics 2.10.0
Go · PyPI
86Excellenthealth index
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 9Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
Go · PyPI
86Excellenthealth index
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 3Jul 16, 2026
MITJul 16, 2026 · metrics 2.10.0
Go
86Excellenthealth index
sisaku-security/sisakulint
CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
Go★ 42Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
npm · PyPI
84Excellenthealth index
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 7,189/moAug 22, 2026
AGPL-3.0Aug 22, 2026 · metrics 2.10.0
PyPI · npm
84Excellenthealth index
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1,281↓ 10.9K/moAug 24, 2026
MITAug 24, 2026 · metrics 2.10.0
PyPI
84Excellenthealth index
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 50Aug 22, 2026
Custom licenseAug 22, 2026 · metrics 2.10.0
Go · npm
83Excellenthealth index
CodesWhat/portwing
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 4Aug 15, 2026
AGPL-3.0Aug 15, 2026 · metrics 2.10.0
Go
83Excellenthealth index
liatrio/autogov
Unified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 1Aug 1, 2026
Apache-2.0Aug 1, 2026 · metrics 2.10.0
Go
81Excellenthealth index
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 23, 2026
Apache-2.0Jul 23, 2026 · metrics 2.10.0
npm · PyPI
80Excellenthealth index
delimit-ai/delimit-mcp-server
The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.
Python · JavaScript★ 21↓ 3,625/moAug 3, 2026
MITAug 3, 2026 · metrics 2.10.0
PyPI
78Goodhealth index
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
Go
78Goodhealth index
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 24Jul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 2.10.0
Go
77Goodhealth index
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 0Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
Go
77Goodhealth index
jitpass/jit
Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and local-first.
Go★ 157Sep 5, 2026
Custom licenseSep 5, 2026 · metrics 2.10.0
Go
75Goodhealth index
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 2Jul 21, 2026
BSD-3-ClauseJul 21, 2026 · metrics 2.10.0
PyPI · npm
75Goodhealth index
gautamvarmadatla/mcpsafetywarden
MCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Python★ 9↓ 2,923/moAug 1, 2026
Custom licenseAug 1, 2026 · metrics 2.10.0