Software Supply Chain Security

13 repos

Tools and infrastructure for securing the software supply chain, from code provenance and artifact signing to dependency analysis and security scoring. The cluster centers on establishing trust and transparency in open-source software through mechanisms like code signing (Sigstore), artifact transparency logs (Rekor), and automated security assessments (OpenSSF Scorecard). Most repos are written in Go with supporting JavaScript and Python tooling, spanning both CLI utilities and web-based frontends for auditing and validating software artifacts.

Go · 6
JavaScript · 2
Python · 2
Makefile · 1
Shell · 1
TypeScript · 1
supply-chain ·6,721
security ·6,721
software-supply-chain ·1,958
software-supply-chain-security ·1,958
sbom ·1,583
graph ·1,540
in-toto ·1,540
cyclonedx ·1,540
cyclonedx-sbom ·1,540
attestations ·1,540