An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
☆772Dec 11, 2024Updated last year
Alternatives and similar repositories for chain-bench
Users that are interested in chain-bench are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆21Nov 24, 2022Updated 3 years ago
- ☆17Sep 4, 2025Updated last year
- The perfect package to work with packages locally☆18May 28, 2022Updated 4 years ago
- ☆14Oct 1, 2026Updated last week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆547Updated this week
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- Linux Runtime Security and Forensics using eBPF☆4,635Oct 1, 2026Updated last week
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆889Aug 31, 2026Updated last month
- A reading list for software supply-chain security.☆364Nov 21, 2022Updated 3 years ago
- Security configuration checks for popular cloud native applications and infrastructure.☆119Feb 16, 2022Updated 4 years ago
- Threat matrix for CI/CD Pipeline☆771May 31, 2026Updated 4 months ago
- Notice: Postee is no longer under active development or maintenance.☆204Aug 31, 2026Updated last month
- Keyless Git signing using Sigstore☆1,128Updated this week
- OWASP Foundation Web Respository☆621Sep 11, 2026Updated 3 weeks ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆625Feb 10, 2026Updated 7 months ago
- in-toto is a framework to protect supply chain integrity.☆1,050Aug 27, 2026Updated last month
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,553Updated this week
- ☆430Jan 18, 2023Updated 3 years ago
- Code signing and transparency for containers and binaries☆6,355Updated this week
- Cloud Security Posture Management (CSPM)☆3,777Sep 22, 2026Updated 2 weeks ago
- Evaluate source control (GitHub) security posture☆251Mar 8, 2023Updated 3 years ago
- Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more☆38,312Updated this week
- Compares and analyzes GCP IAM roles.☆78Mar 9, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Open source compliance tool for development platforms.☆286Oct 30, 2023Updated 2 years ago
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆9,658Updated this week
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆380Jun 7, 2026Updated 4 months ago
- Documenting your Threat Models with HCL☆465Sep 27, 2026Updated last week
- Tfsec is now part of Trivy☆7,048Mar 25, 2026Updated 6 months ago
- Supply-chain Levels for Software Artifacts☆1,940Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,745Updated this week
- library for adding comments to git PRs☆16Aug 19, 2026Updated last month
- Vulnerability scanning just got lazier☆330Sep 25, 2026Updated 2 weeks ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Language-agnostic SLSA provenance generation for Github Actions☆603Aug 7, 2026Updated 2 months ago
- Takes a software bill of materials and outputs provenance, and activity data from trustypkg.dev☆10May 19, 2025Updated last year
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆74Updated this week
- OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure☆1,460May 25, 2026Updated 4 months ago
- Automating situational awareness for cloud penetration tests.☆2,600Aug 20, 2026Updated last month
- Crowdsourced list of sensitive IAM Actions☆158Oct 29, 2024Updated last year
- Trivy's misconfiguration scanning engine☆214Jan 23, 2025Updated last year