A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and other resources. The taxonomy as well as related safeguards can be explored using an interactive visualization tool.
☆82Aug 7, 2026Updated last week
Alternatives and similar repositories for risk-explorer-for-software-supply-chains
Users that are interested in risk-explorer-for-software-supply-chains are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This repository complements our paper by offering the training dataset, the best-performing models utilized in our real-world experiment,…☆22Mar 7, 2025Updated last year
- Feed parsing for language package manager updates☆90Jun 1, 2026Updated 2 months ago
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆375Jun 7, 2026Updated 2 months ago
- ☆22Jul 16, 2025Updated last year
- A place to systematically store software bill of materials (SBOM) documents.☆51Jun 1, 2023Updated 3 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A fork of Bandit tool with patterns to identifying malicious python code.☆31Sep 1, 2022Updated 3 years ago
- DepTrim automatically specializes the software supply chain of dependencies in Maven projects https://arxiv.org/pdf/2302.08370☆15Jun 5, 2026Updated 2 months ago
- Web app to grade your assessments anywhere☆12Dec 31, 2025Updated 7 months ago
- Web app to grade your assessments anywhere☆24Jan 26, 2026Updated 6 months ago
- Collection of tools for analyzing open source packages.☆370Jul 31, 2026Updated 2 weeks ago
- Some stuff about the TCP flags field in NetFlow/IPFIX Data☆12Dec 31, 2015Updated 10 years ago
- A taxonomy of all official CycloneDX property namespaces and names☆25Updated this week
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆150Jan 28, 2024Updated 2 years ago
- Free DSSE Attestation Online Decoder Tool☆15Jul 26, 2026Updated 3 weeks ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Experimental script to query rebuilderd for results☆14Dec 4, 2023Updated 2 years ago
- Source code and data about our large scale study about Java annotaion in practice☆12Apr 14, 2023Updated 3 years ago
- ☆13Feb 11, 2022Updated 4 years ago
- action language providing open class mechanism to xtend/java☆25Oct 11, 2023Updated 2 years ago
- ☆17Nov 24, 2025Updated 8 months ago
- Kestrel Jupyter Notebook Kernel☆10Oct 19, 2023Updated 2 years ago
- a project repository for a paper☆22May 4, 2024Updated 2 years ago
- MUSIC: MUtation analySIs tool with High Configurability and Extensibility☆18Apr 24, 2026Updated 3 months ago
- A modular MCP server providing AI-driven vulnerability management skills, including severity classification and automated insights.☆34Updated this week
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ☆14Dec 10, 2021Updated 4 years ago
- Search Rekor for entries☆47Mar 23, 2026Updated 4 months ago
- This repository contains a list of papers about software supply chain☆29May 22, 2024Updated 2 years ago
- An open-source dataset of malicious software packages found in the wild, 100% vetted by humans.☆372Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆599Updated this week
- Getting started with Decisions-Disruptions☆11Jan 28, 2020Updated 6 years ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers…☆145Updated this week
- Scan pypi for typosquatting☆37Jan 23, 2023Updated 3 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A standard API specification for exchanging supply chain artifacts and intelligence☆111Updated this week
- Governance Platform by @NC3-LU☆13Updated this week
- Comparison of Chainguard Images to others☆21Updated this week
- Descartes supports developers to improve their test suites by reporting weak spots in covered code☆127Jul 25, 2026Updated 3 weeks ago
- Data about all known supply-chain attacks through history☆78Updated this week
- Sharing software supply chain security open source projects☆54Dec 19, 2022Updated 3 years ago
- Demos for our research on Github actions script injection vulnerabilities☆13May 14, 2024Updated 2 years ago