全部标签
目录标签

#supply-chain-security

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

51 条记录
标签为“supply-chain-security”按健康指数排序
Go
98卓越健康指数
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 5702026年7月16日
Apache-2.02026年7月16日 · 指标 2.10.0
npm
96卓越健康指数
NodeSecure/js-x-ray
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
TypeScript★ 286↓ 14.6K/月2026年8月4日
MIT2026年8月4日 · 指标 2.10.0
PyPI · npm
94卓越健康指数
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/月2026年7月16日
Apache-2.02026年7月16日 · 指标 2.10.0
PyPI · npm
94卓越健康指数
sattyamjjain/agent-audit-kit
Static scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2,808/月2026年8月2日
MIT2026年8月2日 · 指标 2.10.0
PyPI · crates.io · npm
93卓越健康指数
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript★ 557↓ 95.5K/月2026年9月5日
Apache-2.02026年9月5日 · 指标 2.10.0
Go · npm
92优秀健康指数
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 4642026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
Go
90优秀健康指数
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 542026年7月21日
Apache-2.02026年7月21日 · 指标 2.10.0
npm
90优秀健康指数
lirantal/npq
safely install npm packages by auditing them pre-install stage
JavaScript★ 1,759↓ 35.4K/月2026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
crates.io
90优秀健康指数
nolabs-ai/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3,0162026年7月16日
Apache-2.02026年7月16日 · 指标 2.10.0
crates.io
89优秀健康指数
always-further/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3,0362026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
crates.io
89优秀健康指数
lukehinds/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3,0472026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
Go · npm
89优秀健康指数
seebom-labs/BOMHort
About standalone, Kubernetes-native Software Bill of Materials (SBOM) visualization and governance platform
Go · TypeScript★ 282026年7月29日
Apache-2.02026年7月29日 · 指标 2.10.0
Go · PyPI
87优秀健康指数
IronSecCo/ironclaw
Security-first, self-hosted AI agents - isolation you can prove, not just promise.
Go★ 192026年8月29日
AGPL-3.02026年8月29日 · 指标 2.10.0
Go
86优秀健康指数
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 02026年7月24日
Apache-2.02026年7月24日 · 指标 2.10.0
Go · PyPI
86优秀健康指数
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 92026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
Go · PyPI
86优秀健康指数
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 32026年7月16日
MIT2026年7月16日 · 指标 2.10.0
Go
86优秀健康指数
sisaku-security/sisakulint
CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
Go★ 422026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
npm · PyPI
84优秀健康指数
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 7,189/月2026年8月22日
AGPL-3.02026年8月22日 · 指标 2.10.0
PyPI · npm
84优秀健康指数
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1,281↓ 10.9K/月2026年8月24日
MIT2026年8月24日 · 指标 2.10.0
PyPI
84优秀健康指数
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 502026年8月22日
自定义许可证2026年8月22日 · 指标 2.10.0
Go · npm
83优秀健康指数
CodesWhat/portwing
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 42026年8月15日
AGPL-3.02026年8月15日 · 指标 2.10.0
Go
83优秀健康指数
liatrio/autogov
Unified CLI for software supply-chain governance / verify GitHub artifact attestations, evaluate OPA/Rego policies, generate SLSA Verification Summary Attestations (VSAs), and manage releases.
Go★ 12026年8月1日
Apache-2.02026年8月1日 · 指标 2.10.0
Go
81优秀健康指数
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 82026年7月23日
Apache-2.02026年7月23日 · 指标 2.10.0
npm · PyPI
80优秀健康指数
delimit-ai/delimit-mcp-server
The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.
Python · JavaScript★ 21↓ 3,625/月2026年8月3日
MIT2026年8月3日 · 指标 2.10.0
PyPI
78良好健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
Go
78良好健康指数
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 242026年7月20日
Apache-2.02026年7月20日 · 指标 2.10.0
Go
77良好健康指数
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 02026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
Go
77良好健康指数
jitpass/jit
Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and local-first.
Go★ 1572026年9月5日
自定义许可证2026年9月5日 · 指标 2.10.0
Go
75良好健康指数
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 22026年7月21日
BSD-3-Clause2026年7月21日 · 指标 2.10.0
PyPI · npm
75良好健康指数
gautamvarmadatla/mcpsafetywarden
MCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Python★ 9↓ 2,923/月2026年8月1日
自定义许可证2026年8月1日 · 指标 2.10.0