A compilation of resources in the software supply chain security domain, with emphasis on open source
380
643 commits
updated Jun 7, 2026
A compilation of resources in the software supply chain security domain, with emphasis on open source.
There is no prescribed taxonomy for this domain. This list will necessarily have some overlap with disciplines and categories such as DevSecOps, SAST, SCA and more.
The supply-chain-synthesis repo offers a long-form read on why that's the case, plus helpful pointers to understand and navigate it as it evolves.
For awesome-software-supply-chain-security we take the following high-level approach: different actors in the supply chain contribute attestations to the elements represented in the chain.
In this process-centric view, attestations are emitted, augmented (e.g., during composition) and verified.
Another way to look at this was described here by Josh Bressers, and here's a narrative example in the wild from Spotify
Using this lens we can identify a large group of "subjects" (dependencies), distinct categories of "facts" (licenses or vulnerabilities) and the specific role of identity, provenance and build systems. This is the rationale behind the current headings, which are expected to evolve with the domain.
Other examples of the ongoing process to define the domain include Add Bad Design as a supply chain scenario · Issue #249 · slsa-framework/slsa and How does SLSA fit into broader supply chain security? · Issue #276 · slsa-framework/slsa. Check out this tweet from Aeva Black with Dan Lorenc for another in-a-pinch view of a couple key projects.
This section includes: package management, library management, dependency management, vendored dependency management, by-hash searches, package, library and dependency naming, library behavior labeling, library publishing, registries and repositories, publishing gates and scans, dependency lifecycle.
MATCH (p:Product)-[:SOURCED_FROM*1..5]->(s:Supplier)), supplier relationship graphs, and real-time anomaly detection across complex supply networks.purl, CPE or another form of ecosystem:name:version, or alternatively via hash):
curl:
uses: eltociear/skill-audit-mcp@v1), multi-arch Docker (ghcr.io/eltociear/skill-audit-mcp:v1), and hosted x402 API. Zero dependencies. 68+ real CVEs disclosed using this ruleset.npm install callsAlso read:
This section includes: package/library scanners and detectors, SBOM formats, standards, authoring and validation, and a few applications. Will likely include SCA.
The most complete reference is awesomeSBOM/awesome-sbom. Another helpful repo focusing on generators is cybeats/sbomgen: List of SBOM Generation Tools.
AppSec Santa — SCA Tools - Curated comparison of SCA tools with features, pricing, and alternatives.
OWASP's SCA tools list is comprehensive on its own
Mend SCA SBOM, Mend Bolt: Find and Fix Open Source vulnerabilities and Whitesource Renovate: Automated Dependency Updates
JFrog Xray - Universal Component Analysis & Container Security Scanning
guacsec/trustify provides a searchable abstraction over CycloneDX/SPDX SBOMs, cross-referencing against security advisories to identify vulnerabilities. See docs
trustification/trustification: A collection of services for storing and managing SBOMs and VEX documents (Bombastic, Vexination, V11y, Collectorist, Spog) with vulnerability lookup, impact analysis, search, and sharing capabilities via Helm chart or single binary
eclipse-sw360/sw360 is an open source software component catalogue for managing software components, licenses, and compliance with SPDX support. See eclipse.dev/sw360/
oss-review-toolkit/ort: A suite of tools to assist with reviewing Open Source Software dependencies.
fosslight/fosslight: FOSSLight is an integrated open source management system that supports the open source software lifecycle, including dependency analysis, license compliance, and SBOM generation. See fosslight.org
fsfe/reuse-tool: REUSE is a tool to check and annotate source files with SPDX license identifiers, making license and copyright information machine-readable. See reuse.software
anchore/syft: CLI tool and library for generating a Software Bill of Materials from container images and filesystems from Software supply chain security solutions • Anchore
ANNOUNCE: Scan is now in maintenance mode · Issue #352 · ShiftLeftSecurity/sast-scan
Aqua Cloud Native Security, Container Security & Serverless Security
Nix-specific SBOM tools for generating precise SBOMs from Nix derivations:
REA-Products/C-SCRM-Use-Case at master · rjb4standards/REA-Products from this tweet
Phylum Analyze PR Action: GitHub Action to analyze Pull Requests for open-source supply chain issues from Phylum | The Software Supply Chain Security Company
microsoft/component-detection: Scans your project to determine what components you use
Software Identification (SWID) Tagging | CSRC and Guidelines for the Creation of Interoperable Software Identification (SWID) Tags
hughsie/python-uswid: A tiny tool for embedding CoSWID tags in EFI binaries
ckotzbauer/sbom-operator: Catalogue all images of a Kubernetes cluster to multiple targets with Syft
Security problem management in Dynatrace Application Security
DefectDojo/django-DefectDojo: DefectDojo is a DevSecOps and vulnerability management tool.
swingletree-oss/swingletree: Integrate and observe the results of your CI/CD pipeline tools
BBVA/susto: Systematic Universal Security Testing Orchestration
AppThreat/rosa: An experiment that looks very promising so far.
FOSSA's SBOM Solution
opensbom-generator/spdx-sbom-generator: Support CI generation of SBOMs via golang tooling.
Tauruseer's SBOM tools
Fortress: Software Bill of Materials
Cybeats SBOM Studio
DeepBOM from Deepbits, an AI-powered platform for SBOM management, vulnerability assessment, malware detection and license compliance
edgebitio/edgebit-build: GitHub action to upload SBOMs to EdgeBit and receive vulnerability context in your pull requests from EdgeBit - Real-time supply chain security, enabling security teams to target and coordinate vulnerability remediation without toil.
Veracode's SCA to Automate Security Scanning, see demo: How to generate a Software Bill of Materials (SBOM) using Veracode Software Composition Analysis
Enterprise Edition - BluBracket: Code Security & Secret Detection
Sonatype OSS Index is a free service that catalogs open source components and identifies known vulnerabilities, available via web and REST API. Integrations include:
tap8stry/orion: Go beyond package manager discovery for SBOM
SoftwareDesignLab/SBOM-in-a-Box, a unified platform for SBOM generation (using integrated open source tools), conversion (SPDX/CycloneDX), VEX generation, quality metrics, comparison and merging
philips-software/SPDXMerge: Tool for merging multiple SPDX JSON/Tag-value SBOMs into a parent SBOM, supporting deep merge (consolidate contents) and shallow merge (create references) with GitHub Action and Docker support
interlynk-io/sbomqs: SBOM quality score - Quality metrics for your sboms
eBay/sbom-scorecard: Generate a score for your sbom to understand if it will actually be useful.
Sbomify: SBOM platform with attestation verification support using Sigstore and GitHub attestations, SPDX 2.3 export, product lifecycle management, and compliance tracking. Read: Announcing Sbomify v0.25: Attestations
Read: An Empirical Study of the SBOM Landscape, a deep-dive into 6 SBOM tools and the accuracy of the SBOMs they produce for complex open-source Java projects (IEEE Security & Privacy, 2023)
Read: OWASP CycloneDX — Authoritative Guide to SBOM, a comprehensive PDF guide on Software Bill of Materials, formats, and best practices
SBOM Insights blog covering SBOM compliance frameworks (NTIA minimum elements, BSI standards), quality scoring with sbomqs, and practical SBOM use cases
cyfinoid/aibommaker: AI BOM Generator, a client-side web tool for analyzing GitHub repositories for AI/LLM usage and generating AI Bills of Materials in CycloneDX 1.7 and SPDX 3.0.1 formats with hardware, infrastructure, and governance detection
trustification/AIBOM-generator: Generate AI Bills of Materials for Hugging Face models, documenting AI model dependencies and provenance
Trusera/ai-bom: AI Bill of Materials generator for agent workflows, scanning n8n, LangGraph, and CrewAI workflows for AI components and generating SBOM output in CycloneDX and SPDX formats
Lab700xOrg/aisbom: Static malware and license scanner for ML model files, disassembling Pickle bytecode and parsing SafeTensors/GGUF binary headers to detect RCE-capable payloads and license risks before model load; generates CycloneDX/SPDX SBOMs and supports remote HTTP-range scanning of Hugging Face models with no weights downloaded.
More interesting resources:
A few open source projects are documenting, in public, how they acquire dependencies. This intentional, human-parsable, long-form examples can be illustrative:
A dedicated section on VEX reads:
Also see:
This section includes: admission and ingestion policies, pull-time verification and end-user verifications.
npm install/npm ci replacementhadolint rules on package installation, e.g., hadolint/README.md at d16f342c8e70fcffc7a788d122a1ba602075250d · hadolint/hadolint
Also see:
And a few things to watch beyond libraries and software dependencies:
This section includes: projects and discussions specifics to developer identity, OIDC, keyrings and related topics.
gitThis section includes: reference architectures and authoritative compilations of supply chain attacks and the emerging categories.
Also see:
This section includes: reproducible builds, hermetic builds, bootstrappable builds, special considerations for CI/CD systems, best practices building artifacts such as OCI containers, etc.
in-toto metadata which can be used with apt-transport-in-toto or dnf-plugin-in-toto to validate reproducible status.init, add, push) and Sigstore bundle format used by ChainloopAlso see:
apko pattern, see Shopify/hanselAnd a collection of reads and listens, ranging from insightful blog posts, explainers/all-rounders and some long-form analysis (we've tried to keep deep dive reads scoped to other sections)
A compilation of resources in the software supply chain security domain, with emphasis on open source
380
643 commits
updated Jun 7, 2026
A compilation of resources in the software supply chain security domain, with emphasis on open source.
There is no prescribed taxonomy for this domain. This list will necessarily have some overlap with disciplines and categories such as DevSecOps, SAST, SCA and more.
The supply-chain-synthesis repo offers a long-form read on why that's the case, plus helpful pointers to understand and navigate it as it evolves.
For awesome-software-supply-chain-security we take the following high-level approach: different actors in the supply chain contribute attestations to the elements represented in the chain.
In this process-centric view, attestations are emitted, augmented (e.g., during composition) and verified.
Another way to look at this was described here by Josh Bressers, and here's a narrative example in the wild from Spotify
Using this lens we can identify a large group of "subjects" (dependencies), distinct categories of "facts" (licenses or vulnerabilities) and the specific role of identity, provenance and build systems. This is the rationale behind the current headings, which are expected to evolve with the domain.
Other examples of the ongoing process to define the domain include Add Bad Design as a supply chain scenario · Issue #249 · slsa-framework/slsa and How does SLSA fit into broader supply chain security? · Issue #276 · slsa-framework/slsa. Check out this tweet from Aeva Black with Dan Lorenc for another in-a-pinch view of a couple key projects.
This section includes: package management, library management, dependency management, vendored dependency management, by-hash searches, package, library and dependency naming, library behavior labeling, library publishing, registries and repositories, publishing gates and scans, dependency lifecycle.
MATCH (p:Product)-[:SOURCED_FROM*1..5]->(s:Supplier)), supplier relationship graphs, and real-time anomaly detection across complex supply networks.purl, CPE or another form of ecosystem:name:version, or alternatively via hash):
curl:
uses: eltociear/skill-audit-mcp@v1), multi-arch Docker (ghcr.io/eltociear/skill-audit-mcp:v1), and hosted x402 API. Zero dependencies. 68+ real CVEs disclosed using this ruleset.npm install callsAlso read:
This section includes: package/library scanners and detectors, SBOM formats, standards, authoring and validation, and a few applications. Will likely include SCA.
The most complete reference is awesomeSBOM/awesome-sbom. Another helpful repo focusing on generators is cybeats/sbomgen: List of SBOM Generation Tools.
AppSec Santa — SCA Tools - Curated comparison of SCA tools with features, pricing, and alternatives.
OWASP's SCA tools list is comprehensive on its own
Mend SCA SBOM, Mend Bolt: Find and Fix Open Source vulnerabilities and Whitesource Renovate: Automated Dependency Updates
JFrog Xray - Universal Component Analysis & Container Security Scanning
guacsec/trustify provides a searchable abstraction over CycloneDX/SPDX SBOMs, cross-referencing against security advisories to identify vulnerabilities. See docs
trustification/trustification: A collection of services for storing and managing SBOMs and VEX documents (Bombastic, Vexination, V11y, Collectorist, Spog) with vulnerability lookup, impact analysis, search, and sharing capabilities via Helm chart or single binary
eclipse-sw360/sw360 is an open source software component catalogue for managing software components, licenses, and compliance with SPDX support. See eclipse.dev/sw360/
oss-review-toolkit/ort: A suite of tools to assist with reviewing Open Source Software dependencies.
fosslight/fosslight: FOSSLight is an integrated open source management system that supports the open source software lifecycle, including dependency analysis, license compliance, and SBOM generation. See fosslight.org
fsfe/reuse-tool: REUSE is a tool to check and annotate source files with SPDX license identifiers, making license and copyright information machine-readable. See reuse.software
anchore/syft: CLI tool and library for generating a Software Bill of Materials from container images and filesystems from Software supply chain security solutions • Anchore
ANNOUNCE: Scan is now in maintenance mode · Issue #352 · ShiftLeftSecurity/sast-scan
Aqua Cloud Native Security, Container Security & Serverless Security
Nix-specific SBOM tools for generating precise SBOMs from Nix derivations:
REA-Products/C-SCRM-Use-Case at master · rjb4standards/REA-Products from this tweet
Phylum Analyze PR Action: GitHub Action to analyze Pull Requests for open-source supply chain issues from Phylum | The Software Supply Chain Security Company
microsoft/component-detection: Scans your project to determine what components you use
Software Identification (SWID) Tagging | CSRC and Guidelines for the Creation of Interoperable Software Identification (SWID) Tags
hughsie/python-uswid: A tiny tool for embedding CoSWID tags in EFI binaries
ckotzbauer/sbom-operator: Catalogue all images of a Kubernetes cluster to multiple targets with Syft
Security problem management in Dynatrace Application Security
DefectDojo/django-DefectDojo: DefectDojo is a DevSecOps and vulnerability management tool.
swingletree-oss/swingletree: Integrate and observe the results of your CI/CD pipeline tools
BBVA/susto: Systematic Universal Security Testing Orchestration
AppThreat/rosa: An experiment that looks very promising so far.
FOSSA's SBOM Solution
opensbom-generator/spdx-sbom-generator: Support CI generation of SBOMs via golang tooling.
Tauruseer's SBOM tools
Fortress: Software Bill of Materials
Cybeats SBOM Studio
DeepBOM from Deepbits, an AI-powered platform for SBOM management, vulnerability assessment, malware detection and license compliance
edgebitio/edgebit-build: GitHub action to upload SBOMs to EdgeBit and receive vulnerability context in your pull requests from EdgeBit - Real-time supply chain security, enabling security teams to target and coordinate vulnerability remediation without toil.
Veracode's SCA to Automate Security Scanning, see demo: How to generate a Software Bill of Materials (SBOM) using Veracode Software Composition Analysis
Enterprise Edition - BluBracket: Code Security & Secret Detection
Sonatype OSS Index is a free service that catalogs open source components and identifies known vulnerabilities, available via web and REST API. Integrations include:
tap8stry/orion: Go beyond package manager discovery for SBOM
SoftwareDesignLab/SBOM-in-a-Box, a unified platform for SBOM generation (using integrated open source tools), conversion (SPDX/CycloneDX), VEX generation, quality metrics, comparison and merging
philips-software/SPDXMerge: Tool for merging multiple SPDX JSON/Tag-value SBOMs into a parent SBOM, supporting deep merge (consolidate contents) and shallow merge (create references) with GitHub Action and Docker support
interlynk-io/sbomqs: SBOM quality score - Quality metrics for your sboms
eBay/sbom-scorecard: Generate a score for your sbom to understand if it will actually be useful.
Sbomify: SBOM platform with attestation verification support using Sigstore and GitHub attestations, SPDX 2.3 export, product lifecycle management, and compliance tracking. Read: Announcing Sbomify v0.25: Attestations
Read: An Empirical Study of the SBOM Landscape, a deep-dive into 6 SBOM tools and the accuracy of the SBOMs they produce for complex open-source Java projects (IEEE Security & Privacy, 2023)
Read: OWASP CycloneDX — Authoritative Guide to SBOM, a comprehensive PDF guide on Software Bill of Materials, formats, and best practices
SBOM Insights blog covering SBOM compliance frameworks (NTIA minimum elements, BSI standards), quality scoring with sbomqs, and practical SBOM use cases
cyfinoid/aibommaker: AI BOM Generator, a client-side web tool for analyzing GitHub repositories for AI/LLM usage and generating AI Bills of Materials in CycloneDX 1.7 and SPDX 3.0.1 formats with hardware, infrastructure, and governance detection
trustification/AIBOM-generator: Generate AI Bills of Materials for Hugging Face models, documenting AI model dependencies and provenance
Trusera/ai-bom: AI Bill of Materials generator for agent workflows, scanning n8n, LangGraph, and CrewAI workflows for AI components and generating SBOM output in CycloneDX and SPDX formats
Lab700xOrg/aisbom: Static malware and license scanner for ML model files, disassembling Pickle bytecode and parsing SafeTensors/GGUF binary headers to detect RCE-capable payloads and license risks before model load; generates CycloneDX/SPDX SBOMs and supports remote HTTP-range scanning of Hugging Face models with no weights downloaded.
More interesting resources:
A few open source projects are documenting, in public, how they acquire dependencies. This intentional, human-parsable, long-form examples can be illustrative:
A dedicated section on VEX reads:
Also see:
This section includes: admission and ingestion policies, pull-time verification and end-user verifications.
npm install/npm ci replacementhadolint rules on package installation, e.g., hadolint/README.md at d16f342c8e70fcffc7a788d122a1ba602075250d · hadolint/hadolint
Also see:
And a few things to watch beyond libraries and software dependencies:
This section includes: projects and discussions specifics to developer identity, OIDC, keyrings and related topics.
gitThis section includes: reference architectures and authoritative compilations of supply chain attacks and the emerging categories.
Also see:
This section includes: reproducible builds, hermetic builds, bootstrappable builds, special considerations for CI/CD systems, best practices building artifacts such as OCI containers, etc.
in-toto metadata which can be used with apt-transport-in-toto or dnf-plugin-in-toto to validate reproducible status.init, add, push) and Sigstore bundle format used by ChainloopAlso see:
apko pattern, see Shopify/hanselAnd a collection of reads and listens, ranging from insightful blog posts, explainers/all-rounders and some long-form analysis (we've tried to keep deep dive reads scoped to other sections)