Усі теги
Тег каталогу

#supply-chain-security

Усі репозиторії публічного реєстру з цим тегом — із тем GitHub або ключових слів, які публікують їхні реєстри пакетів. Здоров'я вимірюється за тією ж версіонованою методологією, що й решта реєстру.

51 запис
З тегом «supply-chain-security»Упорядковано за індексом здоров'я
Go
98Винятковийіндекс здоров'я
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016 лип. 2026 р.
Apache-2.016 лип. 2026 р. · метрики 2.10.0
npm
96Винятковийіндекс здоров'я
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
TypeScript★ 286↓ 14.6K/міс4 серп. 2026 р.
MIT4 серп. 2026 р. · метрики 2.10.0
PyPI · npm
94Винятковийіндекс здоров'я
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5 301/міс16 лип. 2026 р.
Apache-2.016 лип. 2026 р. · метрики 2.10.0
PyPI · npm
94Винятковийіндекс здоров'я
sattyamjjain/agent-audit-kit
Static scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2 808/міс2 серп. 2026 р.
MIT2 серп. 2026 р. · метрики 2.10.0
PyPI · crates.io · npm
93Винятковийіндекс здоров'я
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript★ 557↓ 95.5K/міс5 вер. 2026 р.
Apache-2.05 вер. 2026 р. · метрики 2.10.0
Go · npm
92Відміннийіндекс здоров'я
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 46417 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
Go
90Відміннийіндекс здоров'я
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 5421 лип. 2026 р.
Apache-2.021 лип. 2026 р. · метрики 2.10.0
npm
90Відміннийіндекс здоров'я
lirantal/npq
safely install npm packages by auditing them pre-install stage
JavaScript★ 1 759↓ 35.4K/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
crates.io
90Відміннийіндекс здоров'я
nolabs-ai/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3 01616 лип. 2026 р.
Apache-2.016 лип. 2026 р. · метрики 2.10.0
crates.io
89Відміннийіндекс здоров'я
always-further/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3 03617 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
crates.io
89Відміннийіндекс здоров'я
lukehinds/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3 04719 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 2.10.0
Go · npm
89Відміннийіндекс здоров'я
seebom-labs/BOMHort
About standalone, Kubernetes-native Software Bill of Materials (SBOM) visualization and governance platform
Go · TypeScript★ 2829 лип. 2026 р.
Apache-2.029 лип. 2026 р. · метрики 2.10.0
Go · PyPI
87Відміннийіндекс здоров'я
IronSecCo/ironclaw
Security-first, self-hosted AI agents - isolation you can prove, not just promise.
Go★ 1929 серп. 2026 р.
AGPL-3.029 серп. 2026 р. · метрики 2.10.0
Go
86Відміннийіндекс здоров'я
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 024 лип. 2026 р.
Apache-2.024 лип. 2026 р. · метрики 2.10.0
Go · PyPI
86Відміннийіндекс здоров'я
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
Go · PyPI
86Відміннийіндекс здоров'я
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 316 лип. 2026 р.
MIT16 лип. 2026 р. · метрики 2.10.0
Go
86Відміннийіндекс здоров'я
sisaku-security/sisakulint
CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
Go★ 4219 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 2.10.0
npm · PyPI
84Відміннийіндекс здоров'я
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 7 189/міс22 серп. 2026 р.
AGPL-3.022 серп. 2026 р. · метрики 2.10.0
PyPI · npm
84Відміннийіндекс здоров'я
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1 281↓ 10.9K/міс24 серп. 2026 р.
MIT24 серп. 2026 р. · метрики 2.10.0
PyPI
84Відміннийіндекс здоров'я
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 5022 серп. 2026 р.
Власна ліцензія22 серп. 2026 р. · метрики 2.10.0
Go · npm
83Відміннийіндекс здоров'я
CodesWhat/portwing
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 415 серп. 2026 р.
AGPL-3.015 серп. 2026 р. · метрики 2.10.0
Go
83Відміннийіндекс здоров'я
liatrio/autogov
Unified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 11 серп. 2026 р.
Apache-2.01 серп. 2026 р. · метрики 2.10.0
Go
81Відміннийіндекс здоров'я
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 823 лип. 2026 р.
Apache-2.023 лип. 2026 р. · метрики 2.10.0
npm · PyPI
80Відміннийіндекс здоров'я
delimit-ai/delimit-mcp-server
The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.
Python · JavaScript★ 21↓ 3 625/міс3 серп. 2026 р.
MIT3 серп. 2026 р. · метрики 2.10.0
PyPI
78Добрийіндекс здоров'я
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1 928/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 2.10.0
Go
78Добрийіндекс здоров'я
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 2420 лип. 2026 р.
Apache-2.020 лип. 2026 р. · метрики 2.10.0
Go
77Добрийіндекс здоров'я
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 2.10.0
Go
77Добрийіндекс здоров'я
jitpass/jit
Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and local-first.
Go★ 1575 вер. 2026 р.
Власна ліцензія5 вер. 2026 р. · метрики 2.10.0
Go
75Добрийіндекс здоров'я
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 221 лип. 2026 р.
BSD-3-Clause21 лип. 2026 р. · метрики 2.10.0
PyPI · npm
75Добрийіндекс здоров'я
gautamvarmadatla/mcpsafetywarden
MCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Python★ 9↓ 2 923/міс1 серп. 2026 р.
Власна ліцензія1 серп. 2026 р. · метрики 2.10.0