Усі теги
Тег каталогу

#supply-chain-security

Усі репозиторії публічного реєстру з цим тегом — із тем GitHub або ключових слів, які публікують їхні реєстри пакетів. Здоров'я вимірюється за тією ж версіонованою методологією, що й решта реєстру.

51 запис
З тегом «supply-chain-security»Упорядковано за індексом здоров'я
Go
75Добрийіндекс здоров'я
saschagrunert/nri-supply-chain
NRI plugin for supply chain attestation verification.
Go★ 29 серп. 2026 р.
Apache-2.09 серп. 2026 р. · метрики 2.10.0
PyPI
73Добрийіндекс здоров'я
b7n0de/proofbundle
Offline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth
Python★ 2↓ 6 574/міс23 лип. 2026 р.
MIT23 лип. 2026 р. · метрики 2.10.0
Go
73Добрийіндекс здоров'я
github/actions-lockfile
The authoritative definition of the GitHub Actions dependency lockfile format, plus a Go parser for auditing and verifying the action pins in use across a repo's workflows.
Go★ 33 серп. 2026 р.
MIT3 серп. 2026 р. · метрики 2.10.0
PyPI · npm
71Добрийіндекс здоров'я
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6 171/міс19 лип. 2026 р.
Apache-2.019 лип. 2026 р. · метрики 2.10.0
Go
69Добрийіндекс здоров'я
optimuslabs-io/grokpatrol
Open-source, offline forensic scanner CLI tool designed to detect evidence of git repo collection or upload by the Grok Build CLI to xAI infrastructure.
Go★ 1218 лип. 2026 р.
Apache-2.018 лип. 2026 р. · метрики 2.10.0
Go · npm
67Добрийіндекс здоров'я
codeswhat/lookout
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 316 лип. 2026 р.
Власна ліцензія16 лип. 2026 р. · метрики 2.10.0
crates.io
67Добрийіндекс здоров'я
pulseengine/sigil
Sigil — Supply chain security for WebAssembly. Embedded signatures, Sigstore keyless signing, SLSA provenance. Part of the PulseEngine toolchain.
Rust★ 05 серп. 2026 р.
Без ліцензії5 серп. 2026 р. · метрики 2.10.0
npm
67Добрийіндекс здоров'я
starloghq/index
Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.
TypeScript★ 9↓ 591/міс6 вер. 2026 р.
Власна ліцензія6 вер. 2026 р. · метрики 2.10.0
Go
67Добрийіндекс здоров'я
tiagosilva07/zyrax-guard
Audit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 228 серп. 2026 р.
MIT28 серп. 2026 р. · метрики 2.10.0
crates.io
65Добрийіндекс здоров'я
sebastienrousseau/dtt
Rust crate for date, time, and timezone manipulation. Parse, format, validate, and convert RFC 3339 / ISO 8601 with guaranteed round-trip safety.
Rust★ 7↓ 5 328/міс25 лип. 2026 р.
Apache-2.025 лип. 2026 р. · метрики 2.10.0
Go
63Помірнийіндекс здоров'я
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 2.10.0
PyPI
62Помірнийіндекс здоров'я
sunglasses-dev/sunglasses
Sunglasses for AI agents. Protection layer + neighborhood watch.
Python★ 4↓ 2 911/міс18 серп. 2026 р.
MIT18 серп. 2026 р. · метрики 2.10.0
npm
60Помірнийіндекс здоров'я
calllint/calllint
Pre-flight risk linting for MCP and agent tools — check the blast radius before your agent runs them.
TypeScript · HTML★ 2↓ 3 504/міс31 лип. 2026 р.
Apache-2.031 лип. 2026 р. · метрики 2.10.0
Go
59Помірнийіндекс здоров'я
Goryudyuma/gomod-cooldown
Delay newly available Go module versions during dependency updates with a temporary local GOPROXY.
Go★ 015 лип. 2026 р.
MIT15 лип. 2026 р. · метрики 2.10.0
Packagist
59Помірнийіндекс здоров'я
andreapollastri/checkpoint
Laravel Security Tool
PHP★ 114↓ 19.3K/міс22 серп. 2026 р.
MIT22 серп. 2026 р. · метрики 2.10.0
Go
57Помірнийіндекс здоров'я
Conalh/tofulock
Lock & verify Terraform/OpenTofu module sources by commit digest - the integrity providers get from the native lockfile, but modules don't.
Go★ 027 лип. 2026 р.
MIT27 лип. 2026 р. · метрики 2.10.0
Go
56Помірнийіндекс здоров'я
sairintechnologycom/pkgsafe
Supply-chain firewall for AI coding agents and developers — checks npm/PyPI packages against OSV advisories, typosquat & lifecycle-script heuristics, and your policy before install. Local-first, MCP-native.
Go★ 015 лип. 2026 р.
MIT15 лип. 2026 р. · метрики 2.10.0
Go · npm
54Помірнийіндекс здоров'я
undont/supplyscan
scan JavaScript lockfiles to detect supply chain vulnerabilities and known exploits
Go★ 022 лип. 2026 р.
MIT22 лип. 2026 р. · метрики 2.10.0
PyPI
54Помірнийіндекс здоров'я
zrk222/code-factory
Proof-first software factory for AI-assisted code: specs, adversarial gates, deterministic decisions, and reviewable receipts.
Python★ 0↓ 2 590/міс17 лип. 2026 р.
Власна ліцензія17 лип. 2026 р. · метрики 2.10.0
PyPI
53Помірнийіндекс здоров'я
meidielo/aes-256-gcm-python-tool
Reviewable AES-256-GCM educational tool with Argon2id, JSON envelopes, and safe-mode streaming.
Python · HTML★ 0↓ 77/міс19 лип. 2026 р.
MIT19 лип. 2026 р. · метрики 2.10.0
Go
47Слабкийіндекс здоров'я
wille/gh-actions-cli
Harden and manage your GitHub Actions: SHA-pin every action, enforce allowlist policies, update interactively, and analyze run health
Go★ 317 лип. 2026 р.
MIT17 лип. 2026 р. · метрики 2.10.0