全部标签
目录标签

#supply-chain

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

16 条记录
标签为“supply-chain”按健康指数排序
Go · npm
84良好健康指数
mindersec/minder
Software Supply Chain Security Platform
Go★ 4122026年7月20日
Apache-2.02026年7月20日 · 指标 1.13.0
Go
82良好健康指数
Sigstore/rekor
Software Supply Chain Transparency Log
Go★ 1,1772026年7月18日
Apache-2.02026年7月18日 · 指标 1.13.0
PyPI · npm
80良好健康指数
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/月2026年7月16日
Apache-2.02026年7月16日 · 指标 1.13.0
Go
76良好健康指数
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 542026年7月21日
Apache-2.02026年7月21日 · 指标 1.13.0
npm · Maven · NuGet +1
76良好健康指数
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1,012↓ 719.2K/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
npm · PyPI
71良好健康指数
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 14.1K/月2026年7月14日
AGPL-3.02026年7月14日 · 指标 1.13.0
npm
71良好健康指数
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2,247/月2026年7月15日
MIT2026年7月15日 · 指标 1.13.0
npm
66中等健康指数
blamejs/pki
Pure-JavaScript PKI toolkit that owns its stack — X.509, ASN.1/DER, CMS, PQC-first.
JavaScript★ 1↓ 11.7K/月2026年7月23日
Apache-2.02026年7月23日 · 指标 1.13.0
PyPI · npm
62中等健康指数
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6,171/月2026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0
npm
62中等健康指数
abpai/harness-doctor
Framework-agnostic agent-harness doctor: deterministic checks for good agent-harness practices
TypeScript★ 0↓ 6,723/月2026年7月23日
MIT2026年7月23日 · 指标 1.13.0
Go
61中等健康指数
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 12026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0
npm · PyPI
59中等健康指数
HikaruEgashira/pmsec
Zero-config supply-chain hardening.
PowerShell · Shell · Python★ 3↓ 3,872/月2026年7月15日
MIT2026年7月15日 · 指标 1.13.0
npm
54中等健康指数
adamsjack711-ux/pkgxray
Local CLI/MCP tool that audits AI-agent extensions and npm packages for supply-chain risk. Zero-dep Node. Static scan + OSV vuln precheck + sandboxed quarantine.
JavaScript★ 6↓ 4,133/月2026年7月17日
MIT2026年7月17日 · 指标 1.13.0
npm
53中等健康指数
nkratk/llm-trust-guard
该仓库未发布描述。
TypeScript★ 1↓ 3,299/月2026年7月19日
MIT2026年7月19日 · 指标 1.13.0
npm
49存在风险健康指数
iyulab/formulab
TypeScript library of 174 research-backed industrial engineering formulas across 14 domains — quality, metallurgy, logistics, safety, machining, and more — with zero dependencies.
TypeScript★ 0↓ 2,186/月2026年7月15日
MIT2026年7月15日 · 指标 1.13.0
PyPI
39存在风险健康指数
pypa/pip-audit
Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them
Python★ 1,333↓ 24.2M/月2026年7月20日
Apache-2.02026年7月20日 · 指标 1.13.0