Усі теги
Тег каталогу

#supply-chain-security

Усі репозиторії публічного реєстру з цим тегом — із тем GitHub або ключових слів, які публікують їхні реєстри пакетів. Здоров'я вимірюється за тією ж версіонованою методологією, що й решта реєстру.

33 записи
З тегом «supply-chain-security»Упорядковано за індексом здоров'я
Go
85Відміннийіндекс здоров'я
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016 лип. 2026 р.
Apache-2.016 лип. 2026 р. · метрики 1.13.0
PyPI · npm
80Добрийіндекс здоров'я
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5 301/міс16 лип. 2026 р.
Apache-2.016 лип. 2026 р. · метрики 1.13.0
npm
77Добрийіндекс здоров'я
lirantal/npq
safely install npm packages by auditing them pre-install stage
JavaScript★ 1 759↓ 35.4K/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
Go · npm
77Добрийіндекс здоров'я
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 46417 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
Go
76Добрийіндекс здоров'я
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 5421 лип. 2026 р.
Apache-2.021 лип. 2026 р. · метрики 1.13.0
crates.io
75Добрийіндекс здоров'я
always-further/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3 03617 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
crates.io
75Добрийіндекс здоров'я
lukehinds/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3 04719 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 1.13.0
crates.io
74Добрийіндекс здоров'я
nolabs-ai/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3 01616 лип. 2026 р.
Apache-2.016 лип. 2026 р. · метрики 1.13.0
npm · PyPI
71Добрийіндекс здоров'я
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 14.1K/міс14 лип. 2026 р.
AGPL-3.014 лип. 2026 р. · метрики 1.13.0
Go · PyPI
71Добрийіндекс здоров'я
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
Go · PyPI
71Добрийіндекс здоров'я
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 316 лип. 2026 р.
MIT16 лип. 2026 р. · метрики 1.13.0
Go
71Добрийіндекс здоров'я
sisaku-security/sisakulint
CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
Go★ 4219 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 1.13.0
PyPI · npm
70Добрийіндекс здоров'я
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript · JavaScript★ 39615 лип. 2026 р.
Власна ліцензія15 лип. 2026 р. · метрики 1.13.0
PyPI
68Помірнийіндекс здоров'я
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1 928/міс17 лип. 2026 р.
Apache-2.017 лип. 2026 р. · метрики 1.13.0
Go
67Помірнийіндекс здоров'я
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 2420 лип. 2026 р.
Apache-2.020 лип. 2026 р. · метрики 1.13.0
PyPI
67Помірнийіндекс здоров'я
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/міс14 лип. 2026 р.
Власна ліцензія14 лип. 2026 р. · метрики 1.13.0
Go
66Помірнийіндекс здоров'я
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 821 лип. 2026 р.
Apache-2.021 лип. 2026 р. · метрики 1.13.0
Go
65Помірнийіндекс здоров'я
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 1.13.0
Go
64Помірнийіндекс здоров'я
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 221 лип. 2026 р.
BSD-3-Clause21 лип. 2026 р. · метрики 1.13.0
PyPI
64Помірнийіндекс здоров'я
b7n0de/proofbundle
Offline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth
Python★ 2↓ 6 574/міс23 лип. 2026 р.
MIT23 лип. 2026 р. · метрики 1.13.0
PyPI · npm
62Помірнийіндекс здоров'я
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6 171/міс19 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 1.13.0
Go
61Помірнийіндекс здоров'я
optimuslabs-io/grokpatrol
Open-source, offline forensic scanner CLI tool designed to detect evidence of git repo collection or upload by the Grok Build CLI to xAI infrastructure.
Go★ 1218 лип. 2026 р.
Apache-2.018 лип. 2026 р. · метрики 1.13.0
Go · npm
60Помірнийіндекс здоров'я
codeswhat/lookout
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 316 лип. 2026 р.
Власна ліцензія16 лип. 2026 р. · метрики 1.13.0
npm
59Помірнийіндекс здоров'я
starloghq/index
Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.
TypeScript★ 7↓ 2 182/міс15 лип. 2026 р.
Власна ліцензія15 лип. 2026 р. · метрики 1.13.0
Go
58Помірнийіндекс здоров'я
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 1.13.0
Go
56Помірнийіндекс здоров'я
Goryudyuma/gomod-cooldown
Delay newly available Go module versions during dependency updates with a temporary local GOPROXY.
Go★ 015 лип. 2026 р.
MIT15 лип. 2026 р. · метрики 1.13.0
Go
54Помірнийіндекс здоров'я
jitpass/jit
jit is an open-source CLI that finds the plaintext secrets scattered across a Mac and converts them into just-in-time, Touch-ID-gated credentials, without breaking anything that reads them.
Go★ 215 лип. 2026 р.
Власна ліцензія15 лип. 2026 р. · метрики 1.13.0
Go
54Помірнийіндекс здоров'я
sairintechnologycom/pkgsafe
Supply-chain firewall for AI coding agents and developers — checks npm/PyPI packages against OSV advisories, typosquat & lifecycle-script heuristics, and your policy before install. Local-first, MCP-native.
Go★ 015 лип. 2026 р.
MIT15 лип. 2026 р. · метрики 1.13.0
PyPI
54Помірнийіндекс здоров'я
zrk222/code-factory
Proof-first software factory for AI-assisted code: specs, adversarial gates, deterministic decisions, and reviewable receipts.
Python★ 0↓ 2 590/міс17 лип. 2026 р.
Власна ліцензія17 лип. 2026 р. · метрики 1.13.0
Go · npm
53Помірнийіндекс здоров'я
undont/supplyscan
scan JavaScript lockfiles to detect supply chain vulnerabilities and known exploits
Go★ 022 лип. 2026 р.
MIT22 лип. 2026 р. · метрики 1.13.0