All tags
Catalogue tag

#supply-chain-security

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

51 records
Tagged “supply-chain-security”Ranked by health index
Go
75Goodhealth index
saschagrunert/nri-supply-chain
NRI plugin for supply chain attestation verification.
Go★ 2Aug 9, 2026
Apache-2.0Aug 9, 2026 · metrics 2.10.0
PyPI
73Goodhealth index
b7n0de/proofbundle
Offline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth
Python★ 2↓ 6,574/moJul 23, 2026
MITJul 23, 2026 · metrics 2.10.0
Go
73Goodhealth index
github/actions-lockfile
The authoritative definition of the GitHub Actions dependency lockfile format, plus a Go parser for auditing and verifying the action pins in use across a repo's workflows.
Go★ 3Aug 3, 2026
MITAug 3, 2026 · metrics 2.10.0
PyPI · npm
71Goodhealth index
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6,171/moJul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
Go
69Goodhealth index
optimuslabs-io/grokpatrol
Open-source, offline forensic scanner CLI tool designed to detect evidence of git repo collection or upload by the Grok Build CLI to xAI infrastructure.
Go★ 12Jul 18, 2026
Apache-2.0Jul 18, 2026 · metrics 2.10.0
Go · npm
67Goodhealth index
codeswhat/lookout
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 3Jul 16, 2026
Custom licenseJul 16, 2026 · metrics 2.10.0
crates.io
67Goodhealth index
pulseengine/sigil
Sigil — Supply chain security for WebAssembly. Embedded signatures, Sigstore keyless signing, SLSA provenance. Part of the PulseEngine toolchain.
Rust★ 0Aug 5, 2026
No licenseAug 5, 2026 · metrics 2.10.0
npm
67Goodhealth index
starloghq/index
Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.
TypeScript★ 9↓ 591/moSep 6, 2026
Custom licenseSep 6, 2026 · metrics 2.10.0
Go
67Goodhealth index
tiagosilva07/zyrax-guard
Audit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 2Aug 28, 2026
MITAug 28, 2026 · metrics 2.10.0
crates.io
65Goodhealth index
sebastienrousseau/dtt
Rust crate for date, time, and timezone manipulation. Parse, format, validate, and convert RFC 3339 / ISO 8601 with guaranteed round-trip safety.
Rust★ 7↓ 5,328/moJul 25, 2026
Apache-2.0Jul 25, 2026 · metrics 2.10.0
Go
63Moderatehealth index
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 3Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
PyPI
62Moderatehealth index
sunglasses-dev/sunglasses
Sunglasses for AI agents. Protection layer + neighborhood watch.
Python★ 4↓ 2,911/moAug 18, 2026
MITAug 18, 2026 · metrics 2.10.0
npm
60Moderatehealth index
calllint/calllint
Pre-flight risk linting for MCP and agent tools — check the blast radius before your agent runs them.
TypeScript · HTML★ 2↓ 3,504/moJul 31, 2026
Apache-2.0Jul 31, 2026 · metrics 2.10.0
Go
59Moderatehealth index
Goryudyuma/gomod-cooldown
Delay newly available Go module versions during dependency updates with a temporary local GOPROXY.
Go★ 0Jul 15, 2026
MITJul 15, 2026 · metrics 2.10.0
Packagist
59Moderatehealth index
andreapollastri/checkpoint
Laravel Security Tool
PHP★ 114↓ 19.3K/moAug 22, 2026
MITAug 22, 2026 · metrics 2.10.0
Go
57Moderatehealth index
Conalh/tofulock
Lock & verify Terraform/OpenTofu module sources by commit digest - the integrity providers get from the native lockfile, but modules don't.
Go★ 0Jul 27, 2026
MITJul 27, 2026 · metrics 2.10.0
Go
56Moderatehealth index
sairintechnologycom/pkgsafe
Supply-chain firewall for AI coding agents and developers — checks npm/PyPI packages against OSV advisories, typosquat & lifecycle-script heuristics, and your policy before install. Local-first, MCP-native.
Go★ 0Jul 15, 2026
MITJul 15, 2026 · metrics 2.10.0
Go · npm
54Moderatehealth index
undont/supplyscan
scan JavaScript lockfiles to detect supply chain vulnerabilities and known exploits
Go★ 0Jul 22, 2026
MITJul 22, 2026 · metrics 2.10.0
PyPI
54Moderatehealth index
zrk222/code-factory
Proof-first software factory for AI-assisted code: specs, adversarial gates, deterministic decisions, and reviewable receipts.
Python★ 0↓ 2,590/moJul 17, 2026
Custom licenseJul 17, 2026 · metrics 2.10.0
PyPI
53Moderatehealth index
meidielo/aes-256-gcm-python-tool
Reviewable AES-256-GCM educational tool with Argon2id, JSON envelopes, and safe-mode streaming.
Python · HTML★ 0↓ 77/moJul 19, 2026
MITJul 19, 2026 · metrics 2.10.0
Go
47Weakhealth index
wille/gh-actions-cli
Harden and manage your GitHub Actions: SHA-pin every action, enforce allowlist policies, update interactively, and analyze run health
Go★ 3Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0