An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
☆774Dec 11, 2024Updated last year
Alternatives and similar repositories for chain-bench
Users that are interested in chain-bench are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆21Nov 24, 2022Updated 3 years ago
- ☆17Sep 4, 2025Updated 11 months ago
- The perfect package to work with packages locally☆18May 28, 2022Updated 4 years ago
- ☆14Aug 3, 2026Updated last week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆544Updated this week
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated last year
- Linux Runtime Security and Forensics using eBPF☆4,573Updated this week
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆880Mar 28, 2025Updated last year
- A reading list for software supply-chain security.☆365Nov 21, 2022Updated 3 years ago
- Security configuration checks for popular cloud native applications and infrastructure.☆119Feb 16, 2022Updated 4 years ago
- Threat matrix for CI/CD Pipeline☆776May 31, 2026Updated 2 months ago
- Notice: Postee is no longer under active development or maintenance.☆205May 27, 2026Updated 2 months ago
- Keyless Git signing using Sigstore☆1,115Updated this week
- OWASP Foundation Web Respository☆615Jul 17, 2026Updated 3 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆624Feb 10, 2026Updated 6 months ago
- in-toto is a framework to protect supply chain integrity.☆1,026Updated this week
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,524Updated this week
- ☆428Jan 18, 2023Updated 3 years ago
- Code signing and transparency for containers and binaries☆6,199Updated this week
- Cloud Security Posture Management (CSPM)☆3,762Jul 28, 2026Updated last week
- Evaluate source control (GitHub) security posture☆251Mar 8, 2023Updated 3 years ago
- Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more☆37,338Updated this week
- Compares and analyzes GCP IAM roles.☆78Mar 9, 2025Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Open source compliance tool for development platforms.☆286Oct 30, 2023Updated 2 years ago
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆9,373Updated this week
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆374Jun 7, 2026Updated 2 months ago
- Documenting your Threat Models with HCL☆464Updated this week
- Tfsec is now part of Trivy☆7,026Mar 25, 2026Updated 4 months ago
- Supply-chain Levels for Software Artifacts☆1,905Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,624Updated this week
- library for adding comments to git PRs☆15Jun 8, 2026Updated 2 months ago
- Vulnerability scanning just got lazier☆326Aug 1, 2026Updated last week
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Language-agnostic SLSA provenance generation for Github Actions☆591Updated this week
- Takes a software bill of materials and outputs provenance, and activity data from trustypkg.dev☆10May 19, 2025Updated last year
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆73Updated this week
- OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure☆1,462May 25, 2026Updated 2 months ago
- Automating situational awareness for cloud penetration tests.☆2,553May 26, 2026Updated 2 months ago
- Crowdsourced list of sensitive IAM Actions☆158Oct 29, 2024Updated last year
- Trivy's misconfiguration scanning engine☆214Jan 23, 2025Updated last year